Authorization Bypass Through User-Controlled Key
CVE-2021-36032
Summary
Magento Commerce versions prior to 2.3.7-p1, 2.4.2 prior to 2.4.2-p2 and magento/project-community-edition through 2.0.2 are affected by an Improper Input Validation vulnerability. An authenticated attacker can trigger an Insecure Direct Object Reference (IDOR) in the `V1/customers/me` endpoint to achieve Information Exposure and Privilege Escalation.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- LOW
CWE-639 - Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Advisory Timeline
- Published