VYPR
High severity7.5NVD Advisory· Published Jun 28, 2021· Updated Jun 17, 2026

CVE-2021-28583

CVE-2021-28583

Description

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
>= 2.4.0, < 2.4.2-p12.4.2-p1
magento/community-editionPackagist
< 2.3.72.3.7
magento/project-community-editionPackagist
<= 2.0.2

Affected products

16
  • Magento/Magento12 versions
    cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*+ 11 more
    • cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*range: <2.3.6
    • cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*range: <2.3.6
    • cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.3.6:p1:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.3.6:p1:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.1:p1:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.4.1:p1:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.2:*:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.4.2:*:*:*:open_source:*:*:*
  • osv-coords3 versions
    < 2.3.6+ 2 more
    • (no CPE)range: < 2.3.6
    • (no CPE)range: >= 2.4.0, < 2.4.2-p1
    • (no CPE)range: <= 2.0.2
  • Range: unspecified

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.