A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.
{
"cpe": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"extracted_events": [
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.18"
},
{
"introduced": "2.2.0"
},
{
"fixed": "2.2.9"
},
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.2"
}
],
"source": "CPE_RANGE"
}{
"cpe": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"extracted_events": [
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.18"
},
{
"introduced": "2.2.0"
},
{
"fixed": "2.2.9"
},
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.2"
}
],
"source": "CPE_RANGE"
}