CRITICAL9.1
GHSA-fvrf-9428-527m
Backport for CVE-2021-21024 Blind SQLi from Magento 2
Quick fix
GHSA-fvrf-9428-527m — openmage/magento-lts: upgrade to the fixed version with the command below.
composer require openmage/magento-lts:^19.4.13Details
### Impact This vulnerability allows an administrator unauthorized access to restricted resources.
We fixed a vulnerability in the MySQL adapter to prevent SQL injection attacks. This is a backport of CVE-2021-21024 https://helpx.adobe.com/security/products/magento/apsb21-08.html.
### Patches _Has the problem been patched? What versions should users upgrade to?_ > v20.0.9 v19.4.13
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/openmage/magento-lts
Introduced in:
0Fixed in: 19.4.13Fix
composer require openmage/magento-lts:^19.4.13Packagist/openmage/magento-lts
Introduced in:
20.0.0Fixed in: 20.0.9Fix
composer require openmage/magento-lts:^20.0.9