PT-2022-16848 · Shopware · Shopware

Shyim

·

Published

2022-03-09

·

Updated

2022-03-18

·

CVE-2022-24745

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 6.4.8.2
Description The issue affects guest sessions when HTTP cache is enabled, leading to inconsistent experiences for guest users. Setups with Varnish are not affected by this issue.
Recommendations For versions prior to 6.4.8.2, update to version 6.4.8.2 to resolve the issue. For older versions of 6.1, 6.2, and 6.3, consider installing a security plugin as a workaround. As a temporary workaround, consider disabling the HTTP Cache until a patch is available.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24745
GHSA-JP6H-MXHX-PGQH

Affected Products

Shopware