GHSA-v797-hfv8-v2xm
Dashboard / Vulnerabilities / GHSA-v797-hfv8-v2xm
Summary: Magento 2 Community Edition Session Fixation Check
Details: A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7849, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ce/CVE-2019-7849.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ee/CVE-2019-7849.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7849.yaml, https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33, https://web.archive.org/web/20220121011306/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
