Description
A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2.
Remediation
References
Related Vulnerabilities
OpenSSL 7PK - Security Features Vulnerability (CVE-2015-1793)
WordPress Plugin WooCommerce Affiliate-Coupon Affiliates Cross-Site Request Forgery (4.11.3.3)
Joomla! Core 1.7.x Security Bypass (1.7.0 - 1.7.2)
Coppermine Open Redirection Vulnerability (CVE-2015-3922)
Jboss EAP Incomplete List of Disallowed Inputs Vulnerability (CVE-2018-7489)