CVE-2021-32684 Information

Description

magento-scripts contains scripts and configuration used by Create Magento App a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2 after changing the function from synchronous to asynchronous there wasn’t implemented handler in the start stop exec and logs commands effectively making them unusable. Version 1.5.3 contains patches for the problems.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Reference

https://github.com/scandipwa/create-magento-app/commit/89115db7031e181eb8fb4ec2822bc6cab88e7071 https://github.com/scandipwa/create-magento-app/security/advisories/GHSA-52qp-gwwh-qrg4

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.5

Share on: