CVE-2021-32684 Information
Jun 07, 2022
cve
Description
magento-scripts contains scripts and configuration used by Create Magento App a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2 after changing the function from synchronous to asynchronous there wasn’t implemented handler in the start stop exec and logs commands effectively making them unusable. Version 1.5.3 contains patches for the problems.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Reference
https://github.com/scandipwa/create-magento-app/commit/89115db7031e181eb8fb4ec2822bc6cab88e7071 https://github.com/scandipwa/create-magento-app/security/advisories/GHSA-52qp-gwwh-qrg4
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
5.5
Share on: