CVE-2023-41879
Magento LTS's guest order "protect code" can be brute-forced too easily
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.
Magento LTS es el código base oficial de OpenMage LTS. Los pedidos de invitados se pueden ver sin autenticación utilizando una cookie de "guest-view" que contiene el "protect_code" del pedido. Este código tiene 6 caracteres hexadecimales, lo que podría decirse que no es suficiente para evitar un ataque de fuerza bruta. Exponer cada orden requeriría un ataque de fuerza bruta por separado. Este problema se solucionó en las versiones 19.5.1 y 20.1.1.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-09-04 CVE Reserved
- 2023-09-11 CVE Published
- 2024-09-26 CVE Updated
- 2024-09-26 First Exploit
- 2024-10-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-330: Use of Insufficiently Random Values
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1 | Release Notes | |
https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1 | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp | 2024-09-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openmage Search vendor "Openmage" | Magento Search vendor "Openmage" for product "Magento" | < 19.5.1 Search vendor "Openmage" for product "Magento" and version " < 19.5.1" | lts |
Affected
| ||||||
Openmage Search vendor "Openmage" | Magento Search vendor "Openmage" for product "Magento" | >= 20.0.0 < 20.1.1 Search vendor "Openmage" for product "Magento" and version " >= 20.0.0 < 20.1.1" | lts |
Affected
|