{"id":"CVE-2023-41879","aliases":["GHSA-9358-cpvx-c2qp"],"url":"https://o3.security/vulnerability/CVE-2023-41879","summary":"Magento LTS's guest order \"protect code\" can be brute-forced too easily","details":"Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a \"guest-view\" cookie which contains the order's \"protect_code\". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.","published":"2023-09-11T21:14:28.597Z","modified":"2026-08-08T03:47:46.784275592Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"openmage/magento-lts","fixedVersion":"19.5.1"},{"ecosystem":"Packagist","name":"openmage/magento-lts","fixedVersion":"20.1.1"}],"fix":{"url":"https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128","label":"OpenMage/magento-lts@2a2a2fb"},"references":[{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/releases/tag/v19.5.1"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.1.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41879.json"},{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-9358-cpvx-c2qp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41879"},{"type":"FIX","url":"https://github.com/OpenMage/magento-lts/commit/2a2a2fb504247e8966f8ffc2e17d614be5d43128"},{"type":"FIX","url":"https://github.com/OpenMage/magento-lts/commit/31e74ac5d670b10001f88f038046b62367f15877"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:46.784275592Z"}}