A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: adobe
Published: 2019-08-02T21:11:55
Updated: 2019-08-02T21:11:55
Reserved: 2019-02-12T00:00:00
Link: CVE-2019-7855
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-08-02T22:15:14.970
Modified: 2021-07-21T11:39:23.747
Link: CVE-2019-7855
JSON object: View
Redhat Information
No data.
CWE