CVE-2021-32684

magento-scripts contains scripts and configuration used by Create Magento App, a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2, after changing the function from synchronous to asynchronous there wasn't implemented handler in the start, stop, exec, and logs commands, effectively making them unusable. Version 1.5.3 contains patches for the problems.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:scandipwa:magento-scripts:1.5.1:*:*:*:*:node.js:*:*
cpe:2.3:a:scandipwa:magento-scripts:1.5.2:*:*:*:*:node.js:*:*

History

21 Nov 2024, 06:07

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 5.5
v2 : 5.0
v3 : 6.2
References () https://github.com/scandipwa/create-magento-app/commit/89115db7031e181eb8fb4ec2822bc6cab88e7071 - Patch, Third Party Advisory () https://github.com/scandipwa/create-magento-app/commit/89115db7031e181eb8fb4ec2822bc6cab88e7071 - Patch, Third Party Advisory
References () https://github.com/scandipwa/create-magento-app/security/advisories/GHSA-52qp-gwwh-qrg4 - Patch, Third Party Advisory () https://github.com/scandipwa/create-magento-app/security/advisories/GHSA-52qp-gwwh-qrg4 - Patch, Third Party Advisory

29 Jun 2021, 15:36

Type Values Removed Values Added
CWE CWE-670
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.5
CPE cpe:2.3:a:scandipwa:magento-scripts:1.5.1:*:*:*:*:node.js:*:*
cpe:2.3:a:scandipwa:magento-scripts:1.5.2:*:*:*:*:node.js:*:*
References (MISC) https://github.com/scandipwa/create-magento-app/commit/89115db7031e181eb8fb4ec2822bc6cab88e7071 - (MISC) https://github.com/scandipwa/create-magento-app/commit/89115db7031e181eb8fb4ec2822bc6cab88e7071 - Patch, Third Party Advisory
References (CONFIRM) https://github.com/scandipwa/create-magento-app/security/advisories/GHSA-52qp-gwwh-qrg4 - (CONFIRM) https://github.com/scandipwa/create-magento-app/security/advisories/GHSA-52qp-gwwh-qrg4 - Patch, Third Party Advisory

14 Jun 2021, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-14 23:15

Updated : 2024-11-21 06:07


NVD link : CVE-2021-32684

Mitre link : CVE-2021-32684

CVE.ORG link : CVE-2021-32684


JSON object : View

Products Affected

scandipwa

  • magento-scripts
CWE
CWE-670

Always-Incorrect Control Flow Implementation