{"id":"CVE-2017-13761","aliases":["GHSA-vpq9-c67q-23fq"],"url":"https://o3.security/vulnerability/CVE-2017-13761","summary":"Fastly Magento2 sensitive information disclosure","details":"The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses.","published":"2017-09-14T17:29:00.180Z","modified":"2026-07-08T11:49:23.407540Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"fastly/magento2","fixedVersion":"1.2.26"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.fastly.com/security-advisories/vulnerability-fastly-open-source-cdn-module-intended-be-integrated-magento2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:49:23.407540Z"}}