Description
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
Remediation
References
Related Vulnerabilities
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2016-4029)
WordPress Plugin Content Cards Cross-Site Scripting (0.9.6)
WordPress Plugin Member Approval Cross-Site Request Forgery (131109)
MySQL CVE-2016-0594 Vulnerability (CVE-2016-0594)
Apache Tomcat Improper Access Control Vulnerability (CVE-2014-7810)