QUALITY PATCH

ACSD-51846: An "Internal Error" occurs as all levels of REST API payload are not validated

An "Internal Error" occurs as all levels of REST API payload are not validated. Quality patch ACSD-51846 for magento/framework applies to Magento Open Source and Adobe Commerce 2.4.3-p2 to 2.4.5-p7.

Categories
Web API
Components
magento/framework, magento/module-elasticsearch
Origin
adobe-commerce-support
Since QPT
1.1.36

Issue

An "Internal Error" occurs as all levels of REST API payload are not validated.

Steps to reproduce

1. Add a product to the customer's cart. 1. Send the REST API request to rest/V1/carts/mine/estimate-shipping-methods using a wrong attribute "_street._" with a dot in the end. { "address": { "street.": [ "\uc11c\uc6b8 \uac15\ubd81\uad6c \ud55c\ucc9c\ub85c166\uae38 2 (-\uc11c\uc6b8 \uac15\ubd81\uad6c \uc218\uc720\ub3d9 269-36)" ], "city": "pune", "region": null, "country_id": "IN", "postcode": "411015", "customer_id": "2", "firstname": "test", "lastname": "test", "middlename": null, "prefix": null, "suffix": null, "vat_id": null, "company": null, "telephone": "00000000000", "fax": null, "custom_attributes": [] } }

Adobe's page lists 2.4.3-p2 - 2.4.5-p4 as compatible; the versions below are resolved from the current QPT constraints and are the ones the tool will offer.

Install

Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply ACSD-51846. On Cloud, add ACSD-51846 under stage.build.QUALITY_PATCHES in .magento.env.yaml.

For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its ACSD-51846/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.

Patch files and compatible versions

magento/magento2-base >=2.4.3-p2 <2.4.4-p9 || >=2.4.5 <2.4.5-p8 deprecated

Magento Open Source
2.4.5-p7, 2.4.5-p6, 2.4.5-p5, 2.4.5-p4, 2.4.5-p3, 2.4.5-p2, 2.4.5-p1, 2.4.5, 2.4.4-p8, 2.4.4-p7, 2.4.4-p6, 2.4.4-p5, 2.4.4-p4, 2.4.4-p3, 2.4.4-p2, 2.4.4-p1, 2.4.4, 2.4.3-p3, 2.4.3-p2
Adobe Commerce
2.4.5-p7, 2.4.5-p6, 2.4.5-p5, 2.4.5-p4, 2.4.5-p3, 2.4.5-p2, 2.4.5-p1, 2.4.5, 2.4.4-p8, 2.4.4-p7, 2.4.4-p6, 2.4.4-p5, 2.4.4-p4, 2.4.4-p3, 2.4.4-p2, 2.4.4-p1, 2.4.4, 2.4.3-p3, 2.4.3-p2
Patch file
patches/os/ACSD-51846_2.4.5-p2.patch
  • vendor/magento/module-elasticsearch/Model/Adapter/BatchDataMapper/ProductDataMapper.php
  • vendor/magento/framework/Webapi/ServiceInputProcessor.php

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.