CVE-2019-7855Use of Cryptographically Weak Pseudo-Random Number Generator in Magento

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 57.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.1.02.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
GHSA
Magento 2 Community Cryptographic Flaw2022-05-24
OSV
Magento 2 Community Cryptographic Flaw2022-05-24
CVEList
CVE-2019-7855: A cryptograhic flaw in Magento 22019-08-02
CVE-2019-7855 — Magento vulnerability | cvebase