CVE-2021-21031

MEDIUM5.6EPSS 0.17%

Magento Insufficient Session Expiration

Published: 5/24/2022Modified: 2/10/2025
Also known as:GHSA-4h3p-63x6-vwg2BIT-magento-2021-21031

Description

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.6CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

References (3)