CVE-2022-24879
Malfunction of Cross-Site Request Forgery token validation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
Shopware es una plataforma de software de comercio electrónico de código abierto. Las versiones anteriores a 5.7.9 son vulnerables a un funcionamiento inapropiado de la comprobación de tokens de tipo cross-site request forgery (CSRF). En determinadas circunstancias, los tokens de tipo CSRF no eran generados de nuevo y no son comprobados correctamente. Este problema ha sido corregido en la versión 5.7.9. Los usuarios de versiones anteriores pueden intentar mitigar la vulnerabilidad al usar el plugin de seguridad de Shopware
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-04-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/shopware/shopware/security/advisories/GHSA-pf38-v6qj-j23h | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022 | 2022-05-07 | |
https://www.shopware.com/en/changelog-sw5/#5-7-9 | 2022-05-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Shopware Search vendor "Shopware" | Shopware Search vendor "Shopware" for product "Shopware" | >= 5.2.0 < 5.7.9 Search vendor "Shopware" for product "Shopware" and version " >= 5.2.0 < 5.7.9" | - |
Affected
|