Vulnerabilities > CVE-2021-32684 - Always-Incorrect Control Flow Implementation vulnerability in Scandipwa Magento-Scripts 1.5.1/1.5.2

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
scandipwa
CWE-670

Summary

magento-scripts contains scripts and configuration used by Create Magento App, a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2, after changing the function from synchronous to asynchronous there wasn't implemented handler in the start, stop, exec, and logs commands, effectively making them unusable. Version 1.5.3 contains patches for the problems.

Vulnerable Configurations

Part Description Count
Application
Scandipwa
2