GHSA-7h8v-f2g9-39fx
GitHub Security Advisory
Magento 2 Community Edition Cryptographic Flaw
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information with an algorithm that is insufficiently resistant to brute force attacks.
Affected Packages
Packagist
magento/community-edition
Affected versions:
2.1.0
(fixed in 2.1.18)
Packagist
magento/community-edition
Affected versions:
2.2.0
(fixed in 2.2.9)
Packagist
magento/community-edition
Affected versions:
2.3.0
(fixed in 2.3.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 30, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.