Magento LTS's guest order "protect code" can be brute-forced too easily
CVE-2023-41879
What is CVE-2023-41879?
A vulnerability in OpenMage LTS allows unauthorized users to view guest orders without proper authentication. This is facilitated by the use of a 'guest-view' cookie containing a 'protect_code' that is only six hexadecimal characters long, making it susceptible to brute-force attacks. Each order access requires an individual brute-force attempt, increasing the risk of unauthorized access to sensitive order information. The issue has been addressed in updates 19.5.1 and 20.1.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
magento-lts <= 19.5.0 <= 19.5.0
magento-lts >= 20.0.0, <= 20.1.0 <= 20.0.0, 20.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
