Lucene search

K
osvGoogleOSV:GHSA-C4R2-3F9R-RWP8
HistoryMay 24, 2022 - 5:00 p.m.

Magento 2 Community Weak PRNG

2022-05-2417:00:24
Google
osv.dev
6
magento
weak prng
customer registration
security issue

EPSS

0.001

Percentile

35.9%

Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code for customer registration.

EPSS

0.001

Percentile

35.9%