{"id":"GHSA-h7qw-mxrm-c6h2","summary":"Unauthenticated crypto and weak IV in Magento\\Framework\\Encryption","details":"The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.","aliases":["CVE-2016-6485"],"modified":"2025-02-10T20:19:38.465331Z","published":"2019-11-20T01:33:05Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2019-11-19T01:07:44Z","nvd_published_at":null,"cwe_ids":["CWE-327"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6485"},{"type":"WEB","url":"https://github.com/magento/magento2/pull/15017"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2016-6485.yaml"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/07/19/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/07/27/14"}],"affected":[{"package":{"name":"magento/community-edition","ecosystem":"Packagist","purl":"pkg:composer/magento/community-edition"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0"},{"fixed":"2.2.6"}]}],"versions":["2.0.0","2.0.0-rc","2.0.0-rc2","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-rc1","2.1.0-rc2","2.1.0-rc3","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.15","2.1.16","2.1.17","2.1.18","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/11/GHSA-h7qw-mxrm-c6h2/GHSA-h7qw-mxrm-c6h2.json"}},{"package":{"name":"magento/project-community-edition","ecosystem":"Packagist","purl":"pkg:composer/magento/project-community-edition"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0"},{"last_affected":"2.0.2"}]}],"versions":["2.0.0","2.0.0-rc","2.0.0-rc2","2.0.1","2.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/11/GHSA-h7qw-mxrm-c6h2/GHSA-h7qw-mxrm-c6h2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}