CVE-2023-22732
published 2023-01-17CVE-2023-22732: Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.73%
50.1th percentile
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into the Administration session has been added. As a result the user will be logged out when they are inactive. Users are advised to upgrade. There are no known workarounds for this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopware | core | >= 0 < 6.4.18.1 | 6.4.18.1 |
| shopware | platform | < 6.4.18.1 | 6.4.18.1 |
| shopware | platform | >= 0 < 6.4.18.1 | 6.4.18.1 |
| shopware | shopware | < 6.4.18.1 | 6.4.18.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Shopware has Insufficient Session Expiration in Administration
osv·2023-01-20
CVE-2023-22732 [LOW] Shopware has Insufficient Session Expiration in Administration
Shopware has Insufficient Session Expiration in Administration
### Impact
The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time.
### Patches
We added an automatic logout into the Administration, so the user will be logged out when they are inactive.
### References
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
GHSA
Shopware has Insufficient Session Expiration in Administration
ghsa·2023-01-20
CVE-2023-22732 [LOW] CWE-613 Shopware has Insufficient Session Expiration in Administration
Shopware has Insufficient Session Expiration in Administration
### Impact
The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time.
### Patches
We added an automatic logout into the Administration, so the user will be logged out when they are inactive.
### References
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updateshttps://github.com/shopware/platform/commit/cd7a89cbcd3a0428c6d1ef27b3aa15467a722ff6https://github.com/shopware/platform/security/advisories/GHSA-59qg-93jg-236fhttps://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updateshttps://github.com/shopware/platform/commit/cd7a89cbcd3a0428c6d1ef27b3aa15467a722ff6https://github.com/shopware/platform/security/advisories/GHSA-59qg-93jg-236f
2023-01-17
Published