Description
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2012-5073 Vulnerability (CVE-2012-5073)
WordPress Plugin Easy Registration Forms Cross-Site Scripting (1.8.3)
PHP Other Vulnerability (CVE-2014-4670)
WordPress Plugin Export any WordPress data to XML/CSV SQL Injection (1.3.4)
ownCloud Resource Management Errors Vulnerability (CVE-2015-4717)