CVE
- Id
- 93305
- CVE No.
- CVE-2016-6485
- Status
- Candidate
- Description
- The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.
- Phase
- Assigned (20160727)
- Votes
- None (candidate not yet proposed)
- Comments