CVE-2019-8118: Weak Encryption
Published Oct 8, 2019
·Updated
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.
Other sources
PRODSECBUG-2452: User Password is stored in clear
Affected Software
12 affected componentsFixes available
composer/magento/product-community-edition>=2.2, <2.2.10, >=2.3, <2.3.2-p2
composer/magento/community-edition>=2.3.0<2.3.3
2.3.3
composer/magento/community-edition>=2.2.0<2.2.10
2.2.10
composer/magento/community-edition>=2.1.0<2.1.19
2.1.19
Magento Magento>=2.1.0<2.1.19
Magento Magento>=2.1.0<2.1.19
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.3.0<2.3.2
Magento Magento>=2.3.0<2.3.2
Magento Magento=2.3.2
Magento Magento=2.3.2
Remediation
Event History
Oct 8, 2019
Advisory Published
12:00 AM
Nov 5, 2019
CVE Published
via MITRE·10:49 PM
Data Sourced
via MITRE·10:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8118?
CVE-2019-8118 has a high severity due to the use of weak cryptographic functions to store failed login attempts.
2
How do I fix CVE-2019-8118?
To fix CVE-2019-8118, upgrade to Magento 2.1.19, 2.2.10, or 2.3.3 or later.
3
What versions of Magento are affected by CVE-2019-8118?
CVE-2019-8118 affects Magento 2.1 versions prior to 2.1.19, 2.2 versions prior to 2.2.10, and 2.3 versions prior to 2.3.3.
4
What kind of accounts are impacted by CVE-2019-8118?
CVE-2019-8118 specifically impacts customer accounts due to improper storage of login attempt data.
5
Is customer data compromised due to CVE-2019-8118?
Yes, CVE-2019-8118 compromises the security of customer passwords stored in clear text after failed login attempts.