CVE-2022-21652: falha de baixa gravidade em shopware
Insufficient Session Expiration in shopware
Publicada em · Atualizada em
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 3.5epss 0.8%
probabilidade de exploração
0.8%top 45% das CVEs
exploração observada
nãonenhuma fonte reporta
Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Produtos afetados
shopware · shopwareCVEs relacionadas — shopware
No mesmo produto, das mais perigosas para as menos.
CVE-2021-32712MEDIUMInformation leakage in Error HandlerEPSS 1.1%CVE-2022-24892MEDIUMMultiple valid tokens for password reset in ShopwareEPSS 0.9%CVE-2024-42355HIGHShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagEPSS 0.9%CVE-2022-36102MEDIUMAcess control list bypassed via crafted specific URLsEPSS 0.8%CVE-2022-24873MEDIUMNon-Stored Cross-site Scripting in Shopware storefrontEPSS 0.8%CVE-2022-21651MEDIUMOpen redirect in shopwareEPSS 0.8%