CVE-2019-7886: Weak Encryption
A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.
Other sources
PRODSECBUG-2267: Use of insufficiently random values when generating initialization vector
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7886?
CVE-2019-7886 has a moderate severity level due to a weak cryptographic mechanism affecting the initialization vector.
How do I fix CVE-2019-7886?
To fix CVE-2019-7886, upgrade to Magento version 2.1.18, 2.2.9, or 2.3.2.
What versions of Magento are affected by CVE-2019-7886?
CVE-2019-7886 affects Magento versions 2.1 to below 2.1.18, 2.2 to below 2.2.9, and 2.3 to below 2.3.2.
What kind of vulnerability is CVE-2019-7886?
CVE-2019-7886 is a cryptographic vulnerability that uses insufficiently random values in security contexts.
Is it safe to continue using affected versions of Magento with CVE-2019-7886?
It is not safe to use affected versions of Magento with CVE-2019-7886 as it can lead to compromised security.