GHSA-2w26-gmqm-mc5p
GitHub Security Advisory
Magento 2 Community Cryptographic Flaw
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.
Affected Packages
Packagist
magento/community-edition
Affected versions:
2.1.0
(fixed in 2.1.18)
Packagist
magento/community-edition
Affected versions:
2.2.0
(fixed in 2.2.9)
Packagist
magento/community-edition
Affected versions:
2.3.0
(fixed in 2.3.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 19, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.