HIGH
GHSA-xm9f-vxmx-4m58
Data Flow Sanitation Issue Fix
Quick fix
GHSA-xm9f-vxmx-4m58 — openmage/magento-lts: upgrade to the fixed version with the command below.
composer require openmage/magento-lts:^19.4.15Details
### Impact Due to missing sanitation in data flow it was possible for admin users to upload arbitrary executable files to the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/openmage/magento-lts
Introduced in:
0Fixed in: 19.4.15Fix
composer require openmage/magento-lts:^19.4.15Packagist/openmage/magento-lts
Introduced in:
20.0.0Fixed in: 20.0.13Fix
composer require openmage/magento-lts:^20.0.13References
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-xm9f-vxmx-4m58[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-32759[ADVISORY]
- https://github.com/OpenMage/magento-lts/commit/34709ac642d554aa1824892059186dd329db744b[WEB]
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.15[WEB]
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.13[WEB]