First published: Wed Jan 05 2022(Updated: )
Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopware Shopware | >=5.7.3<5.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21652 is a vulnerability in Shopware, an open source e-commerce software platform, where user sessions are not invalidated after a password change.
CVE-2022-21652 has a severity rating of 8.1 (high).
In affected versions of Shopware (up to version 5.7.7), user sessions are not invalidated when the password is changed.
To fix CVE-2022-21652, you should update Shopware to version 5.7.7 or later.
You can find more information about CVE-2022-21652 in the Shopware documentation and the related GitHub links provided.