Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1qcDZoLW14aHgtcGdxaM0xLg
Shopware guest session is shared between customers
Impact
Guest sessions are shared between customers when HTTP cache is enabled. Setups with Varnish are not affected by this issue
Patches
We recommend updating to the current version 6.4.8.2. You can get the update to 6.4.8.2 regularly via the Auto-Updater or directly via the download overview.
https://www.shopware.com/en/download/#shopware-6
Workarounds
Security Plugin
For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Disable HTTP Cache
Disabling HTTP Cache is also a valid workaround
Permalink: https://github.com/advisories/GHSA-jp6h-mxhx-pgqhJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcDZoLW14aHgtcGdxaM0xLg
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: almost 2 years ago
CVSS Score: 4.8
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Identifiers: GHSA-jp6h-mxhx-pgqh, CVE-2022-24745
References:
- https://github.com/shopware/platform/security/advisories/GHSA-jp6h-mxhx-pgqh
- https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-03-2022?_ga=2.159980029.1931762803.1646933116-1088482757.1646933116
- https://nvd.nist.gov/vuln/detail/CVE-2022-24745
- https://github.com/advisories/GHSA-jp6h-mxhx-pgqh
Blast Radius: 10.1
Affected Packages
packagist:shopware/storefront
Dependent packages: 89Dependent repositories: 127
Downloads: 2,457,096 total
Affected Version Ranges: <= 6.4.8.1
Fixed in: 6.4.8.2
All affected versions:
All unaffected versions: 6.0.0, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.2.0, 6.2.1, 6.2.2, 6.2.3
packagist:shopware/platform
Dependent packages: 6Dependent repositories: 38
Downloads: 1,264,935 total
Affected Version Ranges: <= 6.4.8.1
Fixed in: 6.4.8.2
All affected versions:
All unaffected versions: 5.3.1, 6.0.0, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.2.0, 6.2.1, 6.2.2, 6.2.3