Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qrq-r688-vvh4

Опубликовано: 28 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

Multiple valid tokens for password reset in Shopware

Impact

Multiple tokens for password reset could be requested. All tokens could be used to change the password. This makes it possible for an attacker to take over the victims account if s/he gains access to the victims email account and finds unused password reset token in the emails within the time frame of two hours.

Patches

We recommend updating to the current version 5.7.9. You can get the update to 5.7.9 regularly via the Auto-Updater or directly via the download overview. https://www.shopware.com/en/changelog-sw5/#5-7-9

For older versions you can use the Security Plugin: https://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html

References

https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022

Пакеты

Наименование

shopware/shopware

composer
Затронутые версииВерсия исправления

>= 5.0.4, < 5.7.9

5.7.9

EPSS

Процентиль: 51%
0.00285
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 6.4
nvd
почти 4 года назад

Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9.

EPSS

Процентиль: 51%
0.00285
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-640