HIGH
GHSA-26rr-v2j2-25fh
Layout XML Arbitrary Code Fix
Quick fix
GHSA-26rr-v2j2-25fh — openmage/magento-lts: upgrade to the fixed version with the command below.
composer require openmage/magento-lts:^19.4.15Details
### Impact Layout XML enabled admin users to execute arbitrary commands via block methods.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/openmage/magento-lts
Introduced in:
0Fixed in: 19.4.15Fix
composer require openmage/magento-lts:^19.4.15Packagist/openmage/magento-lts
Introduced in:
20.0.0Fixed in: 20.0.13Fix
composer require openmage/magento-lts:^20.0.13References
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-26rr-v2j2-25fh[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-32758[ADVISORY]
- https://github.com/OpenMage/magento-lts/commit/b99307d00b59c4a226a1e3e4083f02cf2fc8fce7[WEB]
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.15[WEB]
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.13[WEB]