5.3
CVSSv3

CVE-2019-8118

Published: 05/11/2019 Updated: 08/11/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Magento 2.1 before 2.1.19, Magento 2.2 before 2.2.10, Magento 2.3 before 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

magento magento

magento magento 2.3.2

Github Repositories

Composer patches for Magento 2

New Document Magento 2 Composer Patches Patches to be applied by githubcom/cweagans/composer-patches Module Name Fixes Affected versions magento/magento2-base Patch-Magento_Base-clipatch Patch-Magento_Base-M22x-clipatch < 220 >=220 magento/magento2-base Patch-Magento_Base-M210-widgets-values-utf8-decodepatch #4232 < 218 (21