Description
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2056 | A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation. |
Github GHSA |
GHSA-2w26-gmqm-mc5p | Magento 2 Community Cryptographic Flaw |
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:02:19.005Z
Reserved: 2019-02-12T00:00:00.000Z
Link: CVE-2019-7855
No data.
Status : Modified
Published: 2019-08-02T22:15:14.970
Modified: 2024-11-21T04:48:52.113
Link: CVE-2019-7855
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA