Description
A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6105)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2011-4317)
WordPress Plugin QR Redirector Security Bypass (1.5)
Moodle Insertion of Sensitive Information into Log File Vulnerability (CVE-2012-1156)
WordPress Plugin Xorbin Digital Flash Clock Cross-Site Scripting (1.0)