Description
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
Remediation
References
Related Vulnerabilities
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1963)
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.18)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.16.68)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-6433)
WordPress Plugin WP Gravity Forms Insightly Cross-Site Scripting (1.0.6)