PT-2022-16848 · Shopware · Shopware
Shyim
·
Published
2022-03-09
·
Updated
2022-03-18
·
CVE-2022-24745
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 6.4.8.2
Description
The issue affects guest sessions when HTTP cache is enabled, leading to inconsistent experiences for guest users. Setups with Varnish are not affected by this issue.
Recommendations
For versions prior to 6.4.8.2, update to version 6.4.8.2 to resolve the issue.
For older versions of 6.1, 6.2, and 6.3, consider installing a security plugin as a workaround.
As a temporary workaround, consider disabling the HTTP Cache until a patch is available.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopware