GHSA-crjc-2v9m-8w7r
Dashboard / Vulnerabilities / GHSA-crjc-2v9m-8w7r
GHSA-crjc-2v9m-8w7r
Summary: Magento improper authorization vulnerability in the integrations module
Details: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-21026, https://github.com/magento/magento2/commit/a2eb7e29ea92a8bbc86c3b6b81b59d8533088497, https://github.com/magento/magento2/commit/a349e022c9ae070e7da262021f9ef182105aa00b, https://github.com/magento/magento2, https://helpx.adobe.com/security/products/magento/apsb21-08.html
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
