Sonatype GuideSonatype Guide
ComponentsVulnerabilitiesPricingMCP
Docs
Sign up
Login
composer
openmage
magento-lts
v19.5.0

magento-lts v19.5.0

openmage
PublishedJul 28, 2023•Policy
compliance
composer Registry
Developer Trust Score
N/A
Recommended Version:x.y.zBest
Latest version with 0 known vulnerabilities that meets your policy.
Compare Versions
Severity
CVSS Score
0.010.0
EPSS Score
0.01.0
Malware
KEV Status
Published
7.5CVE-2023-41879
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.
affected
SeverityHigh
PublishedSep 12, 2023
7.5sonatype-2016-0133
jquery - Uncontrolled Resource Consumption
affected
SeverityHigh
Published
Mar 28, 2017