CVE-2023-41879
Estado: ModificadaAlta (7.5)—
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.25%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-330
Referencias
- https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128
- https://github.com/OpenMage/magento-lts/commit/31e74ac5d670b10001f88f038046b62367f15877
- https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1
- https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp
- https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128
- https://github.com/OpenMage/magento-lts/commit/31e74ac5d670b10001f88f038046b62367f15877
- https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1
- https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-41879",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-41879",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-26T16:53:59.562897Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "OpenMage",
"product": "magento-lts",
"versions": [
{
"status": "affected",
"version": "<= 19.5.0"
},
{
"status": "affected",
"version": ">= 20.0.0, <= 20.1.0"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*"
],
"vendor": "openmage",
"product": "magento",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "19.5.0"
},
{
"status": "affected",
"version": "20.0.0",
"versionType": "custom",
"lessThanOrEqual": "20.1.0"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2023-09-11T22:15:08.267",
"references": [
{
"url": "https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OpenMage/magento-lts/commit/31e74ac5d670b10001f88f038046b62367f15877",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/OpenMage/magento-lts/commit/31e74ac5d670b10001f88f038046b62367f15877",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-330"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a \"guest-view\" cookie which contains the order's \"protect_code\". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1."
},
{
"lang": "es",
"value": "Magento LTS es el código base oficial de OpenMage LTS. Los pedidos de invitados se pueden ver sin autenticación utilizando una cookie de \"guest-view\" que contiene el \"protect_code\" del pedido. Este código tiene 6 caracteres hexadecimales, lo que podría decirse que no es suficiente para evitar un ataque de fuerza bruta. Exponer cada orden requeriría un ataque de fuerza bruta por separado. Este problema se solucionó en las versiones 19.5.1 y 20.1.1."
}
],
"lastModified": "2026-06-17T06:22:59.567",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2C082C2-33B8-42AA-A80D-7FC64CBEA8A4",
"versionEndExcluding": "19.5.1"
},
{
"criteria": "cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C0ACC44D-FE37-4C32-B49F-DD00D3CAA1DA",
"versionEndExcluding": "20.1.1",
"versionStartIncluding": "20.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}