CVE-2022-24744
published 2022-03-09CVE-2022-24744: Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged…
PriorityP414low3.5CVSS 3.1
AVNACLPRLUIRSUCLINAN
EPSS
0.48%
38.0th percentile
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopware | core | >= 0 < 6.4.8.1 | 6.4.8.1 |
| shopware | platform | < 6.4.8.1 | 6.4.8.1 |
| shopware | platform | >= 0 < 6.4.8.1 | 6.4.8.1 |
| shopware | shopware | < 6.4.8.1 | 6.4.8.1 |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Shopware user session is not logged out if the password is reset via password recovery
ghsa·2022-03-10
CVE-2022-24744 [LOW] CWE-613 Shopware user session is not logged out if the password is reset via password recovery
Shopware user session is not logged out if the password is reset via password recovery
### Impact
User session is not logged out if the password is reset via password recovery
## Patches
Fixed in 6.4.8.1, maintainers recommend updating to the current version 6.4.8.2. You can get the update to 6.4.8.2 regularly via the Auto-Updater or directly via the download overview.
https://www.shopware.com/en/download/#shopware-6
## Workarounds
For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659
OSV
Shopware user session is not logged out if the password is reset via password recovery
osv·2022-03-10
CVE-2022-24744 [LOW] Shopware user session is not logged out if the password is reset via password recovery
Shopware user session is not logged out if the password is reset via password recovery
### Impact
User session is not logged out if the password is reset via password recovery
## Patches
Fixed in 6.4.8.1, maintainers recommend updating to the current version 6.4.8.2. You can get the update to 6.4.8.2 regularly via the Auto-Updater or directly via the download overview.
https://www.shopware.com/en/download/#shopware-6
## Workarounds
For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-09
Published