Логотип exploitDog
bind:CVE-2024-31447
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-31447

Количество 2

Количество 2

nvd логотип

CVE-2024-31447

почти 2 года назад

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on `CustomerLogoutEvent` and invalidates the session additionally. The problem has been fixed in Shopware 6.6.1.0 and 6.5.8.8. Those who are unable to update can install the latest version of the Shopware Security Plugin as a workaround.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5297-wrrp-rcj7

почти 2 года назад

Shopware Improper Session Handling in store-api account logout

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-31447

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on `CustomerLogoutEvent` and invalidates the session additionally. The problem has been fixed in Shopware 6.6.1.0 and 6.5.8.8. Those who are unable to update can install the latest version of the Shopware Security Plugin as a workaround.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-5297-wrrp-rcj7

Shopware Improper Session Handling in store-api account logout

CVSS3: 5.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу