Skip to content

Data Flow Sanitation Issue Fix

High
mark-netalico published GHSA-xm9f-vxmx-4m58 Aug 27, 2021

Package

No package listed

Affected versions

< 19.4.13, 20 < 20.0.10

Patched versions

> 19.4.13, 20 > 20.0.11

Description

Impact

Due to missing sanitation in data flow it was possible for admin users to upload arbitrary executable files to the server.

Patches

The latest OpenMage Versions up from v19.4.13 and v20.0.11 have this Issue solved

Severity

High

CVE ID

CVE-2021-32759

Weaknesses

No CWEs