A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-08-02 22:15
Updated : 2024-02-28 17:08
NVD link : CVE-2019-7860
Mitre link : CVE-2019-7860
CVE.ORG link : CVE-2019-7860
JSON object : View
Products Affected
magento
- magento
CWE
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)