← Volver a CVEs
CVE-2022-24879
HIGH7.5
Descripcion
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
Detalles CVE
Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado4/28/2022
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
shopware:shopware
Debilidades (CWE)
CWE-352CWE-352
Referencias
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022(security-advisories@github.com)
https://github.com/shopware/shopware/security/advisories/GHSA-pf38-v6qj-j23h(security-advisories@github.com)
https://www.shopware.com/en/changelog-sw5/#5-7-9(security-advisories@github.com)
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/shopware/shopware/security/advisories/GHSA-pf38-v6qj-j23h(af854a3a-2127-422b-91ae-364da2661108)
https://www.shopware.com/en/changelog-sw5/#5-7-9(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.