Description
A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.
Remediation
References
Related Vulnerabilities
Drupal Core 8.x.x Arbitrary File Overwrite (8.0.0 - 8.7.14)
Oracle HTTP Server Out-of-bounds Write Vulnerability (CVE-2021-4034)
Oracle Database Server CVE-2014-6455 Vulnerability (CVE-2014-6455)
Joomla! Core 3.x.x Security Bypass (3.2.0 - 3.4.4)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5865)