CVE-2021-21012
13.01.2021, 23:15
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.Enginsight
Vendor | Product | Version |
---|---|---|
adobe | magento_commerce | 𝑥 ≤ 2.3.6 |
adobe | magento_commerce | 2.4.0 |
adobe | magento_commerce | 2.4.0:p1 |
adobe | magento_commerce | 2.4.1 |
adobe | magento_open_source | 𝑥 ≤ 2.3.6 |
adobe | magento_open_source | 2.4.0 |
adobe | magento_open_source | 2.4.0:p1 |
adobe | magento_open_source | 2.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration