Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a guest-view cookie which contains the orders protect_code. This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Magento | Openmage | * | 19.5.1 (excluding) |
Magento | Openmage | 20.0.0 (including) | 20.1.1 (excluding) |