HIGH7.2
GHSA-h632-p764-pjqm
DataFlow upload remote code execution vulnerability
Quick fix
GHSA-h632-p764-pjqm — openmage/magento-lts: upgrade to the fixed version with the command below.
composer require openmage/magento-lts:^19.4.22Details
### Impact An administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/openmage/magento-lts
Introduced in:
0Fixed in: 19.4.22Fix
composer require openmage/magento-lts:^19.4.22Packagist/openmage/magento-lts
Introduced in:
20.0.0Fixed in: 20.0.19Fix
composer require openmage/magento-lts:^20.0.19References
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-h632-p764-pjqm[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-41231[ADVISORY]
- https://github.com/OpenMage/magento-lts/commit/d16fc6c5a1e66c6f0d9f82020f11702a7ddd78e4[WEB]
- https://github.com/OpenMage/magento-lts[PACKAGE]
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22[WEB]
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19[WEB]