VYPR

Packagist (Composer) package

magento/project-community-edition

pkg:composer/magento/project-community-edition

Vulnerabilities (161)

  • CVE-2016-6485HigMar 1, 2017
    affected >= 2.0, <= 2.0.2

    The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.

Page 9 of 9