Логотип exploitDog
bind:CVE-2022-21652
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21652

Количество 2

Количество 2

nvd логотип

CVE-2022-21652

около 4 лет назад

Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-p523-jrph-qjc6

около 4 лет назад

Insufficient Session Expiration in shopware

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-21652

Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue.

CVSS3: 3.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-p523-jrph-qjc6

Insufficient Session Expiration in shopware

CVSS3: 3.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу