CVE-2024-31447: Shopware has Improper Session Handling in store-api
Impact
When a authentificated request is made to POST /store-api/account/logout, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on CustomerLogoutEvent and invalidates the session additionally.
Patches The problem has been fixed with Shopware 6.6.1.0 and 6.5.8.8.
Workarounds When you are not able to update, you can install the latest version of the Shopware Security Plugin.
Other sources
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to POST /store-api/account/logout, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on CustomerLogoutEvent and invalidates the session additionally. The problem has been fixed in Shopware 6.6.1.0 and 6.5.8.8. Those who are unable to update can install the latest version of the Shopware Security Plugin as a workaround.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31447?
CVE-2024-31447 has a medium-severity rating due to an authentication issue that allows cart clearing without proper user logout.
How do I fix CVE-2024-31447?
To resolve CVE-2024-31447, upgrade to version 6.6.1.0 or 6.5.8.8 of the affected Shopware packages.
What is the impact of CVE-2024-31447?
The impact of CVE-2024-31447 is that authenticated users can clear their cart without being logged out, potentially leading to confusion or misuse.
Which versions are affected by CVE-2024-31447?
CVE-2024-31447 affects versions from 6.3.5.0 up to 6.6.0.0-rc1 of Shopware platform and core.
Who is impacted by CVE-2024-31447?
Any users utilizing the Shopware platform or core within the specified version range are at risk due to CVE-2024-31447.