Impact
An administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile.
References
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-h632-p764-pjqm
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19
- https://nvd.nist.gov/vuln/detail/CVE-2021-41231
- https://github.com/OpenMage/magento-lts/commit/d16fc6c5a1e66c6f0d9f82020f11702a7ddd78e4
- https://github.com/advisories/GHSA-h632-p764-pjqm