Description
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2471 | Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1. |
Github GHSA |
GHSA-9358-cpvx-c2qp | Magento LTS's guest order "protect code" can be brute-forced too easily |
References
History
Thu, 26 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-26T16:55:58.992Z
Reserved: 2023-09-04T16:31:48.223Z
Link: CVE-2023-41879
Updated: 2024-08-02T19:09:49.294Z
Status : Modified
Published: 2023-09-11T22:15:08.267
Modified: 2024-11-21T08:21:50.350
Link: CVE-2023-41879
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA