CVE-2019-8113: Weak Encryption
Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code for customer registration.
Other sources
PRODSECBUG-2464: Use of weak cryptographic function
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8113?
CVE-2019-8113 is classified as a critical vulnerability due to its potential for brute-force exploitation.
How do I fix CVE-2019-8113?
To fix CVE-2019-8113, upgrade Magento to version 2.2.10 or 2.3.3 and ensure the use of secure cryptographic functions.
What versions of Magento are affected by CVE-2019-8113?
CVE-2019-8113 affects Magento versions prior to 2.2.10 and 2.3.3 or prior to 2.3.2-p1.
Why is CVE-2019-8113 a concern for e-commerce sites?
CVE-2019-8113 is a concern for e-commerce sites because it allows attackers to potentially brute-force customer registration confirmation codes.
What types of attacks are possible due to CVE-2019-8113?
CVE-2019-8113 enables attackers to perform brute-force attacks, compromising the registration security mechanism of Magento sites.