A denial-of-service (DoS) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. By abusing insufficient brute-forcing defenses in the token exchange protocol, an unauthenticated attacker could disrupt transactions between the Magento merchant and PayPal.
                
            References
                    | Link | Resource | 
|---|---|
| https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 | Vendor Advisory | 
| https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 04:48
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 - Vendor Advisory | 
Information
                Published : 2019-08-02 22:15
Updated : 2024-11-21 04:48
NVD link : CVE-2019-7928
Mitre link : CVE-2019-7928
CVE.ORG link : CVE-2019-7928
JSON object : View
Products Affected
                magento
- magento
CWE
                