MEDIUM4.3
GHSA-r3c9-9j5q-pwv4
magento-lts Reset Password not protected against well-timed CSRF
Quick fix
GHSA-r3c9-9j5q-pwv4 — openmage/magento-lts: upgrade to the fixed version with the command below.
composer require openmage/magento-lts:^19.4.22Details
### Impact
Password reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password.
### Patches
PR forthcoming
### Workarounds
None
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/openmage/magento-lts
Introduced in:
0Fixed in: 19.4.22Fix
composer require openmage/magento-lts:^19.4.22Packagist/openmage/magento-lts
Introduced in:
20.0.0Fixed in: 20.0.19Fix
composer require openmage/magento-lts:^20.0.19References
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-r3c9-9j5q-pwv4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-21395[ADVISORY]
- https://hackerone.com/reports/1086752[WEB]
- https://github.com/OpenMage/magento-lts[PACKAGE]
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22[WEB]
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19[WEB]
- https://packagist.org/packages/openmage/magento-lts[WEB]