magento/community-edition Security Advisories for 2.4.1 (64)
-
[MEDIUM] Magento Open Source Improper Authorization vulnerability
PKSA-yx36-4pvc-fy33 CVE-2024-45131 GHSA-xc5p-773w-m3pm
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[HIGH] Magento Open Source Improper Authorization vulnerability
PKSA-g59s-h86c-d272 CVE-2024-45132 GHSA-5f64-ppmg-cvvm
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Information Exposure vulnerability
PKSA-k213-y2gv-f361 CVE-2024-45133 GHSA-j3mh-wx5f-2vhg
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Information Exposure vulnerability
PKSA-fg7g-5j9c-3snf CVE-2024-45134 GHSA-4f89-5cwm-rm5g
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Access Control vulnerability
PKSA-t8cd-w48x-nzyk CVE-2024-45135 GHSA-8pxg-gcp4-57ww
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[LOW] Magento Open Source Improper Access Control vulnerability
PKSA-zp2y-jcbv-86tw CVE-2024-45149 GHSA-w7rg-7wq2-pjrw
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Cross-Site Scripting (XSS) vulnerability
PKSA-w47m-6mjs-p6p5 CVE-2024-45116 GHSA-873m-72g6-853g
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Input Validation vulnerability
PKSA-11qw-117j-ntf6 CVE-2024-45117 GHSA-3fr3-gcqh-3m2g
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[HIGH] Magento Open Source Improper Access Control vulnerability
PKSA-nmsp-4zh6-c2yy CVE-2024-45118 GHSA-cg52-68fv-94qq
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Server-Side Request Forgery (SSRF) vulnerability
PKSA-7ymh-b7jr-kcyn CVE-2024-45119 GHSA-g9fm-wc6h-pvgj
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
PKSA-5bd5-9qvn-r6z1 CVE-2024-45120 GHSA-47jp-46c9-25vf
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Access Control vulnerability
PKSA-5d5h-vdxk-9rb4 CVE-2024-45121 GHSA-2qhq-fw98-h6wg
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Access Control vulnerability
PKSA-trg9-zwtk-rt2y CVE-2024-45122 GHSA-46fm-x82m-5f74
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source reflected Cross-Site Scripting (XSS) vulnerability
PKSA-q3cy-4db7-mxq5 CVE-2024-45123 GHSA-88x2-cq34-5fwc
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Access Control vulnerability
PKSA-g52f-ss82-znpd CVE-2024-45124 GHSA-w3p2-pc3h-69wv
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Incorrect Authorization vulnerability
PKSA-vc9p-z4vk-zhsm CVE-2024-45125 GHSA-xg36-8c2v-jpxh
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source stored Cross-Site Scripting (XSS) vulnerability
PKSA-rc6f-2sj1-779v CVE-2024-45127 GHSA-c89g-gq5r-2xw2
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Authorization vulnerability
PKSA-jqmh-mscm-q45w CVE-2024-45128 GHSA-qpp7-742q-58j3
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Access Control vulnerability
PKSA-8ttm-6rvp-fshh CVE-2024-45129 GHSA-m58h-998x-66f3
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Access Control vulnerability
PKSA-35sf-fj41-ym76 CVE-2024-45130 GHSA-v3v6-jfvw-m576
Affected version: =2.4.4|=2.4.5|=2.4.6|=2.4.7|<2.4.4-p11|>=2.4.5-p1,<2.4.5-p10|>=2.4.6-p1,<2.4.6-p8|>=2.4.7-beta1,<2.4.7-p3
Reported by:
GitHub -
[MEDIUM] Magento Open Source Path Traversal vulnerability
PKSA-dw79-2frq-sm6h CVE-2024-39406 GHSA-6pxh-2557-5cj5
Affected version: =2.4.4|<2.4.4-p10|=2.4.5|>=2.4.5-p1,<2.4.5-p9|=2.4.6|>=2.4.6-p1,<2.4.6-p7|=2.4.7|>=2.4.7-p1,<2.4.7-p2
Reported by:
GitHub -
[MEDIUM] Magento Open Source Cross-Site Request Forgery vulnerability
PKSA-dzsz-sjtm-vq7t CVE-2024-39408 GHSA-4cj6-f32v-6hgx
Affected version: =2.4.4|<2.4.4-p10|=2.4.5|>=2.4.5-p1,<2.4.5-p9|=2.4.6|>=2.4.6-p1,<2.4.6-p7|=2.4.7|>=2.4.7-p1,<2.4.7-p2
Reported by:
GitHub -
[MEDIUM] Magento Open Source Cross-Site Request Forgery (CSRF) vulnerability
PKSA-8qcx-d884-ntny CVE-2024-39409 GHSA-rf4q-m23c-7q8r
Affected version: =2.4.4|<2.4.4-p10|=2.4.5|>=2.4.5-p1,<2.4.5-p9|=2.4.6|>=2.4.6-p1,<2.4.6-p7|=2.4.7|>=2.4.7-p1,<2.4.7-p2
Reported by:
GitHub -
[MEDIUM] Magento Open Source Cross-Site Request Forgery (CSRF) vulnerability
PKSA-x9tz-w7x6-ncgm CVE-2024-39410 GHSA-4323-f82v-f6jr
Affected version: =2.4.4|<2.4.4-p10|=2.4.5|>=2.4.5-p1,<2.4.5-p9|=2.4.6|>=2.4.6-p1,<2.4.6-p7|=2.4.7|>=2.4.7-p1,<2.4.7-p2
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Authorization vulnerability
PKSA-sh88-myrv-9t1n CVE-2024-39412 GHSA-7472-vw39-g2j3
Affected version: =2.4.4|<2.4.4-p10|=2.4.5|>=2.4.5-p1,<2.4.5-p9|=2.4.6|>=2.4.6-p1,<2.4.6-p7|=2.4.7|>=2.4.7-p1,<2.4.7-p2
Reported by:
GitHub -
[MEDIUM] Magento Open Source Server-Side Request Forgery (SSRF) vulnerability
PKSA-zmwm-kwzt-pms6 CVE-2024-34111 GHSA-jmqp-r3gg-6jh3
Affected version: <2.4.4-p9|>=2.4.5-p1,<2.4.5-p8|>=2.4.6-p1,<2.4.6-p6|=2.4.4|=2.4.5|=2.4.6|=2.4.7
Reported by:
GitHub -
[CRITICAL] Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
PKSA-71k8-bhfg-zj3d CVE-2024-34102 GHSA-m8cj-3v68-3cxj
Affected version: =2.4.7|=2.4.6|=2.4.5|<2.4.4-p9|>=2.4.5-p1,<2.4.5-p8|>=2.4.6-p1,<2.4.6-p6|=2.4.4
Reported by:
GitHub -
[HIGH] Magento Open Source Improper Authentication vulnerability
PKSA-29px-skjv-7bmn CVE-2024-34103 GHSA-f7q4-9gwv-6774
Affected version: <2.4.4-p9|>=2.4.5-p1,<2.4.5-p8|>=2.4.6-p1,<2.4.6-p6|=2.4.4|=2.4.5|=2.4.6|=2.4.7
Reported by:
GitHub -
[HIGH] Magento Open Source Improper Authorization vulnerability
PKSA-pbd2-8ctn-8ptb CVE-2024-34104 GHSA-wwj3-573j-rvvm
Affected version: <2.4.4-p9|>=2.4.5-p1,<2.4.5-p8|>=2.4.6-p1,<2.4.6-p6|=2.4.4|=2.4.5|=2.4.6|=2.4.7
Reported by:
GitHub -
[MEDIUM] Magento Open Source Cross-Site Scripting (XSS) vulnerability
PKSA-gc3j-nr7v-3th6 CVE-2024-34105 GHSA-5632-wq7m-gfq9
Affected version: <2.4.4-p9|>=2.4.5-p1,<2.4.5-p8|>=2.4.6-p1,<2.4.6-p6|=2.4.4|=2.4.5|=2.4.6|=2.4.7
Reported by:
GitHub -
[MEDIUM] Magento Open Source Incorrect Authorization vulnerability
PKSA-jfkj-qxdn-854f CVE-2024-34106 GHSA-p6h9-gx5g-wg64
Affected version: <2.4.4-p9|>=2.4.5-p1,<2.4.5-p8|>=2.4.6-p1,<2.4.6-p6|=2.4.4|=2.4.5|=2.4.6|=2.4.7
Reported by:
GitHub -
[MEDIUM] Magento Open Source Improper Access Control vulnerability
PKSA-mw1m-j257-zksc CVE-2024-34107 GHSA-r7cm-g469-wm4g
Affected version: <2.4.4-p9|>=2.4.5-p1,<2.4.5-p8|>=2.4.6-p1,<2.4.6-p6|=2.4.4|=2.4.5|=2.4.6|=2.4.7
Reported by:
GitHub -
[HIGH] Magento Improper input validation vulnerability
PKSA-228k-hrjg-43zp CVE-2022-42344 GHSA-297f-r9w7-w492
Affected version: =2.4.4|>=2.4.0,<2.4.3-p3|<2.3.7-p4
Reported by:
GitHub -
[HIGH] Magento Path Traversal vulnerability
PKSA-rnsh-tzs8-qzqg CVE-2022-34254 GHSA-fx9g-g9q6-x3jx
Affected version: =2.4.4|>=2.4.0,<2.4.3-p3|>=2.3.0,<2.3.7-p4
Reported by:
GitHub -
[HIGH] Magento Improper Access Control vulnerability
PKSA-858j-1s59-ycmj CVE-2022-34255 GHSA-x95x-f4g9-mm85
Affected version: >=2.4.0,<2.4.3-p3|>=2.4.4,<2.4.5|>=2.3.0,<2.3.7-p4
Reported by:
GitHub -
[HIGH] Magento Improper Authorization vulnerability
PKSA-4kq2-8xg5-xc5f CVE-2022-34256 GHSA-r7mm-grf3-5fjv
Affected version: >=2.4.0,<2.4.3-p3|>=2.4.4,<2.4.5|>=2.3.0,<2.3.7-p4
Reported by:
GitHub -
[MEDIUM] Magento stored Cross-Site Scripting (XSS) vulnerability
PKSA-8rxk-pq5k-p21j CVE-2022-34257 GHSA-rg7p-wmgj-f374
Affected version: >=2.4.0,<2.4.3-p3|>=2.4.4,<2.4.5|>=2.3.0,<2.3.7-p4
Reported by:
GitHub -
[MEDIUM] Magento stored Cross-Site Scripting (XSS) vulnerability
PKSA-48rk-jcyb-xpsd CVE-2022-34258 GHSA-5m55-g8pv-x8ww
Affected version: >=2.4.0,<2.4.3-p3|>=2.4.4,<2.4.5|>=2.3.0,<2.3.7-p4
Reported by:
GitHub -
[MEDIUM] Magento Improper Access Control vulnerability
PKSA-1w77-ttnz-wb1k CVE-2022-34259 GHSA-9wjf-94h3-r4rh
Affected version: >=2.4.0,<2.4.3-p3|>=2.4.4,<2.4.5|>=2.3.0,<2.3.7-p4
Reported by:
GitHub -
[CRITICAL] Magento XML Injection vulnerability in the Widgets Module
PKSA-ky72-2cr3-p8cw CVE-2022-34253 GHSA-cj7w-pm77-hvg6
Affected version: >=2.4.0,<2.4.3-p3|>=2.4.4,<2.4.5|<2.3.7-p4
Reported by:
GitHub -
[LOW] Magento Information Disclosure vulnerability
PKSA-rk1n-456t-jj3q CVE-2021-28566 GHSA-w942-fw92-mqm2
Affected version: >=2.3.0,<2.3.7|>=2.4.0,<2.4.2-p1
Reported by:
GitHub -
[MEDIUM] Magento Improper Authorization vulnerability in the customers module
PKSA-98vv-8nyb-ffc5 CVE-2021-28567 GHSA-cc3w-r3w8-hfh7
Affected version: <2.3.7|>=2.4.0,<2.4.2-p1
Reported by:
GitHub -
[MEDIUM] Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
PKSA-8582-qjd4-1g8s CVE-2021-28556 GHSA-39ch-rg26-gmq5
Affected version: <2.3.7|>=2.4.0,<2.4.2-p1
Reported by:
GitHub -
[MEDIUM] Magento Unauthorized access to restricted resources
PKSA-y9kv-15rd-x7qv CVE-2021-28563 GHSA-q9xx-4689-gvv5
Affected version: <2.3.7|>=2.4.0,<2.4.2-p1
Reported by:
GitHub -
[HIGH] Magento Violation of Secure Design Principles vulnerability in RMA PDF filename formats
PKSA-n22f-w4n6-g3fx CVE-2021-28583 GHSA-7gh6-f4jh-3crq
Affected version: <2.3.7|>=2.4.0,<2.4.2-p1
Reported by:
GitHub -
[MEDIUM] Magento Path Traversal vulnerability
PKSA-kfxc-51yz-zbnf CVE-2021-28584 GHSA-7gpv-xrjr-f5h4
Affected version: <2.3.7|>=2.4.0,<2.4.2-p1
Reported by:
GitHub -
[MEDIUM] Magento Improper input validation vulnerability
PKSA-2gm6-m4rp-6fvz CVE-2021-28585 GHSA-c38m-9668-6j2w
Affected version: <2.3.7|>=2.4.0,<2.4.2-p1
Reported by:
GitHub -
[MEDIUM] Magento Insufficient Session Expiration
PKSA-48bg-fxg1-vkpy CVE-2021-21031 GHSA-4h3p-63x6-vwg2
Affected version: <2.3.6|>=2.4.0,<2.4.1-p1
Reported by:
GitHub -
[CRITICAL] Magento XML injection in the Widgets module
PKSA-6mpp-zh74-59gd CVE-2021-21019 GHSA-mw95-gmw4-883p
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6-p1
Reported by:
GitHub -
[MEDIUM] Magento Insecure Direct Object Reference (IDOR) in the product module
PKSA-tw4y-fk6r-w8j9 CVE-2021-21022 GHSA-8pfq-g48p-x7w8
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6-p1
Reported by:
GitHub -
[MEDIUM] Magento stored cross-site scripting vulnerability in the admin console
PKSA-cv47-f2nq-tgnw CVE-2021-21023 GHSA-h5rm-m772-6qcx
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6
Reported by:
GitHub -
[CRITICAL] Magento Blind SQL Injection in the Search module
PKSA-392g-81d8-vhhm CVE-2021-21024 GHSA-rj4f-cp4v-hvcv
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6-p1
Reported by:
GitHub -
[MEDIUM] Magento improper authorization vulnerability in the integrations module
PKSA-m4ck-h7wd-91mj CVE-2021-21026 GHSA-crjc-2v9m-8w7r
Affected version: >=2.4.0,<2.4.2|<2.3.6-p1
Reported by:
GitHub -
[MEDIUM] Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API
PKSA-njqv-gp7y-zc74 CVE-2021-21027 GHSA-h4xc-577p-hgj9
Affected version: >=2.4.0,<2.4.2|<2.3.6-p1
Reported by:
GitHub -
[MEDIUM] Magento Reflected Cross-site Scripting vulnerability via 'file' parameter
PKSA-m8rz-jc2c-7m91 CVE-2021-21029 GHSA-jwxh-wj79-ccm6
Affected version: >=2.4.0,<2.4.2|<2.3.6-p1
Reported by:
GitHub -
[HIGH] Magento stored cross-site scripting (XSS) in the customer address upload feature
PKSA-7rd2-y8tt-4pxt CVE-2021-21030 GHSA-6988-g89m-27vf
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6
Reported by:
GitHub -
[MEDIUM] Magento Insufficient Session Expiration
PKSA-whxx-hqxp-qv8z CVE-2021-21032 GHSA-4jfq-f8hc-775q
Affected version: <2.3.6|>=2.4.0,<2.4.1-p1
Reported by:
GitHub -
[CRITICAL] Magento vulnerable to a file upload restriction bypass
PKSA-yt4p-w22g-fdxr CVE-2021-21014 GHSA-269w-pqc7-68q9
Affected version: >=2.4.0,<2.4.2|<2.3.6-p1
Reported by:
GitHub -
[CRITICAL] Magento OS Command Injection
PKSA-msgn-qz5c-7csr CVE-2021-21018 GHSA-rv48-v862-mp92
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6
Reported by:
GitHub -
[MEDIUM] Magento Improper Access Control
PKSA-rx41-6862-pt82 CVE-2021-21020 GHSA-2j6v-829g-885q
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6
Reported by:
GitHub -
[CRITICAL] Magento XPath Injection
PKSA-q4sd-rbfw-bn9m CVE-2021-21025 GHSA-h437-qjj9-vmq4
Affected version: >=2.4.0,<2.4.1-p1|<2.3.6-p1
Reported by:
GitHub -
[HIGH] Magento OS command injection via the customer attribute save controller
PKSA-q4dq-szdv-ng3x CVE-2021-21015 GHSA-w2p4-2c8c-2g7h
Affected version: >=2.4.0,<2.4.2|<2.3.6-p1
Reported by:
GitHub -
[CRITICAL] Magento OS command injection via the WebAPI
PKSA-g12r-tk3d-rbjb CVE-2021-21016 GHSA-792f-c8mp-2cr5
Affected version: >=2.4.0,<2.4.2|<2.3.6-p1
Reported by:
GitHub -
[CRITICAL] Magento improper input validation vulnerability
PKSA-bck7-ptrd-xq9f CVE-2022-24086 GHSA-f8fv-f786-9933
Affected version: >=2.4.0,<2.4.3-p2|>=2.3.3-p1,<2.3.7-p3
Reported by:
GitHub