Magento Session Fixation Vulnerability - CVE-2019-7849 - Vulnerability Database

Magento Session Fixation Vulnerability - CVE-2019-7849

High
Reference: CVE-2019-7849
Title: Magento Session Fixation Vulnerability
Overview:

A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2 Magento Commerce prior to 1.14.4.2 Magento 2.1 prior to 2.1.18 Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2.