This vulnerability allows an administrator unauthorized access to restricted resources.
We fixed a vulnerability in the MySQL adapter to prevent SQL injection attacks. This is a backport of CVE-2021-21024 https://helpx.adobe.com/security/products/magento/apsb21-08.html.
Has the problem been patched? What versions should users upgrade to?
v20.0.9 v19.4.13
{
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"nvd_published_at": "2021-04-21T21:15:00Z",
"github_reviewed": true,
"github_reviewed_at": "2021-04-21T21:06:43Z"
}