{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-17T02:15:33.184","vulnerabilities":[{"cve":{"id":"CVE-2023-41879","sourceIdentifier":"security-advisories@github.com","published":"2023-09-11T22:15:08.267","lastModified":"2024-11-21T08:21:50.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a \"guest-view\" cookie which contains the order's \"protect_code\". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1."},{"lang":"es","value":"Magento LTS es el código base oficial de OpenMage LTS. Los pedidos de invitados se pueden ver sin autenticación utilizando una cookie de \"guest-view\" que contiene el \"protect_code\" del pedido. Este código tiene 6 caracteres hexadecimales, lo que podría decirse que no es suficiente para evitar un ataque de fuerza bruta. Exponer cada orden requeriría un ataque de fuerza bruta por separado. Este problema se solucionó en las versiones 19.5.1 y 20.1.1."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-330"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*","versionEndExcluding":"19.5.1","matchCriteriaId":"C2C082C2-33B8-42AA-A80D-7FC64CBEA8A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*","versionStartIncluding":"20.0.0","versionEndExcluding":"20.1.1","matchCriteriaId":"C0ACC44D-FE37-4C32-B49F-DD00D3CAA1DA"}]}]}],"references":[{"url":"https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/OpenMage/magento-lts/commit/31e74ac5d670b10001f88f038046b62367f15877","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp","source":"security-advisories@github.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/OpenMage/magento-lts/commit/31e74ac5d670b10001f88f038046b62367f15877","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}