Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish are not affected by this issue. This issue has been resolved in version 6.4.8.2. Users unable to upgrade should disable the HTTP Cache.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1459 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish are not affected by this issue. This issue has been resolved in version 6.4.8.2. Users unable to upgrade should disable the HTTP Cache.
Github GHSA Github GHSA GHSA-jp6h-mxhx-pgqh Shopware guest session is shared between customers
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-23T18:56:09.816Z

Reserved: 2022-02-10T00:00:00.000Z

Link: CVE-2022-24745

cve-icon Vulnrichment

Updated: 2024-08-03T04:20:50.203Z

cve-icon NVD

Status : Modified

Published: 2022-03-09T23:15:08.047

Modified: 2024-11-21T06:51:00.213

Link: CVE-2022-24745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.