New Release 19.4.13 and 20.0.10
Placeholder for the change 1 2
- CVE-2021-21426 3- Fixing a bug in Zend Framework’s Stream HTTP Wrapper
- CVE-2021-21427 4 - Security Update for SQL-injection for Magento 2 (a back-port of CVE-2021-3007 of
laminas-http)
Placeholder for the change 1 2
laminas-http)Placeholder for the change 1 2
Increase composer.json PHP version range to include 8.0 1 2
CVE-2020-15244 3 is our second OpenMage CVE and our first CVE that is wholly independent of Adobe! 1 2

Our Release Today marks a new and Important Milestone for the OpenMage Project. Not even 2 Months since the end of life for Magento 1, we are now shipping the first Security Patch, which is not included in the official Magento 1 Release.