« Volver al listado

CVE-2021-28583

Estado: ModificadaMedia (4.2)—

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-28583",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.2,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.6
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "Magento Commerce",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "2.4.2"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "2.3.6-p1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "2.4.1-p1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "None"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-06-28T14:15:11.073",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/magento/apsb21-30.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/magento/apsb21-30.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-657"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources."
    },
    {
      "lang": "es",
      "value": "Magento versiones 2.4.2 (y anteriores), versiones 2.4.1-p1 (y anteriores) y versiones 2.3.6-p1 (y anteriores), están afectadas por una vulnerabilidad de Violation of Secure Design Principles en los formatos de nombre de archivo RMA PDF. Una explotación con éxito podría permitir a un atacante conseguir acceso no autorizado a recursos restringidos"
    }
  ],
  "lastModified": "2026-06-17T03:46:34.557",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14B6B496-E849-4935-B3D8-8BDB8DDD59A3",
              "versionEndExcluding": "2.3.6"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79C3A2B0-AE14-4D0F-BEE2-82FC00BE6087",
              "versionEndExcluding": "2.3.6"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9C60780-1213-4D06-A4C4-CC915C952B7B"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CCEDD72-7195-495C-A9B6-9D18BA9756F7"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.6:p1:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01879893-5878-4C97-AFEC-267BAC76F700"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.6:p1:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F86F5CAD-F186-4D84-87A0-14205E86E1C1"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80860D39-0D51-47B3-BA92-F473ADA1BBC3"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2ADFE661-AB9C-4387-AC4F-D14A0717C2B8"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.1:p1:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADF35A67-0CE2-4507-B98F-B8819F2BC5E4"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.1:p1:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7917A5AD-F96F-495F-9456-C0EC141200E7"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.2:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC091141-2FD7-4086-B324-557A904ADD30"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.2:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DCC2B03-8867-40DF-9AD9-D05CE59CE6EF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}