CVE-2021-21022

Source
https://cve.org/CVERecord?id=CVE-2021-21022
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21022.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-21022
Aliases
Published
2021-02-11T20:15:14.327Z
Modified
2026-04-10T04:29:28.658118Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could lead to unauthorized access to restricted resources.

References

Affected packages

Git / github.com/magento/devdocs

Affected ranges

Type
GIT
Repo
https://github.com/magento/devdocs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.3.6"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "2.3.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.6-NA"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.6-NA"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.1-NA"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.1-NA"
        }
    ]
}
Type
GIT
Repo
https://github.com/magento/magento2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.0-NA"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.0-NA"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.0-p1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.0-p1"
        }
    ]
}

Affected versions

0.*
0.1.0-alpha100
0.1.0-alpha101
0.1.0-alpha102
0.1.0-alpha103
0.1.0-alpha104
0.1.0-alpha105
0.1.0-alpha106
0.1.0-alpha107
0.1.0-alpha108
0.1.0-alpha89
0.1.0-alpha90
0.1.0-alpha91
0.1.0-alpha92
0.1.0-alpha93
0.1.0-alpha94
0.1.0-alpha95
0.1.0-alpha96
0.1.0-alpha97
0.1.0-alpha98
0.1.0-alpha99
0.42.0-beta1
0.42.0-beta3
0.74.0-beta1
1.*
1.x-eos
2.*
2.0.0
2.0.0-rc
2.0.8
2.1.0
2.1.0-rc1
2.1.0-rc2
2.1.0-rc3
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.2.0-RC1.1
2.2.0-RC1.2
2.2.0-RC1.3
2.2.11
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3-p1
2.3.4
2.3.5
2.3.6-p1
2.4.0
2.4.0-p1
2.4.1-p1
2.4.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21022.json"