Junglewise Threat Intelligence

CVE-2016-6485: Unauthenticated crypto and weak IV in Magento\Framework\Encryption

CVE-2016-6485 · Severity: low · CVSS 3 · Published 2019-11-20

Technologies: magento/community-edition (Packagist), magento/project-community-edition (Packagist). Vendors: Packagist.

Executive brief

Unauthenticated crypto and weak IV in Magento\Framework\Encryption

Affected products

  • Packagist magento/community-edition
  • Packagist magento/project-community-edition

Related threats