CVE-2023-22732
LOW3.7EPSS 0.41%Shopware has Insufficient Session Expiration in Administration
Published: 1/20/2023Modified: 11/8/2023
Description
### Impact The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. ### Patches We added an automatic logout into the Administration, so the user will be logged out when they are inactive. ### References https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
Affected packages (2)
- Packagist/shopware/corefrom 0, < 6.4.18.1
- Packagist/shopware/platformfrom 0, < 6.4.18.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-22732
- PATCHhttps://github.com/shopware/platform
- WEBhttps://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
- WEBhttps://github.com/shopware/platform/commit/cd7a89cbcd3a0428c6d1ef27b3aa15467a722ff6
- WEBhttps://github.com/shopware/platform/security/advisories/GHSA-59qg-93jg-236f