Description
Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code for customer registration.
Remediation
References
Related Vulnerabilities
WordPress Plugin wptf-image-gallery Arbitrary File Download (1.0.3)
Play Framework Inadequate Encryption Strength Vulnerability (CVE-2019-17598)
WordPress Plugin 3xSocializer Cross-Site Scripting (0.98.22)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0.1)
ReviveAdserver Session Fixation Vulnerability (CVE-2017-5831)