CVE-2022-21652: Insufficient Session Expiration in shopware
Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-21652?
CVE-2022-21652 is a vulnerability in Shopware, an open source e-commerce software platform, where user sessions are not invalidated after a password change.
What is the severity of CVE-2022-21652?
CVE-2022-21652 has a severity rating of 8.1 (high).
How does CVE-2022-21652 affect Shopware?
In affected versions of Shopware (up to version 5.7.7), user sessions are not invalidated when the password is changed.
How can I fix CVE-2022-21652 in Shopware?
To fix CVE-2022-21652, you should update Shopware to version 5.7.7 or later.
Where can I find more information about CVE-2022-21652?
You can find more information about CVE-2022-21652 in the Shopware documentation and the related GitHub links provided.