CVE-2021-28566
Magento Commerce information disclosure during upload action leveraging a specially crafted file
3.7
LOW
CVSS 3.1
EPSS 1.4%
Description
Magento versions 2.4.2 (and earlier), 2.4.1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploitation could lead to the disclosure of document root path by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
How to fix CVE-2021-28566
To remediate CVE-2021-28566, upgrade the affected package to a fixed version below.
- —upgrade to 2.4.3 or later
- —upgrade to 2.4.2-p1 or later
Is CVE-2021-28566 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.4.3
- >= 2.4.0, < 2.4.2-p1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |