Skip to main content

Authorization Bypass Through User-Controlled Key

CVE-2021-36032

Severity High
Score 8.3/10

Summary

Magento Commerce versions prior to 2.3.7-p1, 2.4.2 prior to 2.4.2-p2 and magento/project-community-edition through 2.0.2 are affected by an Improper Input Validation vulnerability. An authenticated attacker can trigger an Insecure Direct Object Reference (IDOR) in the `V1/customers/me` endpoint to achieve Information Exposure and Privilege Escalation.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • LOW

CWE-639 - Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Advisory Timeline

  • Published