Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59qg-93jg-236f

Опубликовано: 20 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Shopware has Insufficient Session Expiration in Administration

Impact

The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time.

Patches

We added an automatic logout into the Administration, so the user will be logged out when they are inactive.

References

https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates

Пакеты

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

<= 6.4.18.0

6.4.18.1

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

<= 6.4.18.0

6.4.18.1

EPSS

Процентиль: 61%
0.00407
Низкий

3.7 Low

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 3.7
nvd
около 3 лет назад

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into the Administration session has been added. As a result the user will be logged out when they are inactive. Users are advised to upgrade. There are no known workarounds for this issue.

EPSS

Процентиль: 61%
0.00407
Низкий

3.7 Low

CVSS3

Дефекты

CWE-613