SB2022030940 - Multiple vulnerabilities in Shopware



SB2022030940 - Multiple vulnerabilities in Shopware

Published: March 9, 2022 Updated: May 20, 2026

Security Bulletin ID SB2022030940
CSH Severity
High
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 33% Medium 33% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2022-24745)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access another customer's guest session data.

The vulnerability exists due to improper access control in the guest session handling logic when HTTP cache is enabled. A remote attacker can send requests that reuse a shared guest session to access another customer's guest session data.

Only installations with HTTP cache enabled are vulnerable. Setups using Varnish are not affected.


2) Improper access control (CVE-ID: CVE-2022-24747)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in HTTP caching when handling cached HTTP headers. A remote attacker can trigger caching of private HTTP headers to disclose sensitive information.


3) Improper access control (CVE-ID: CVE-2022-24748)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify customers and create orders without app permission.

The vulnerability exists due to improper access control in app permission enforcement when handling customer modification and order creation operations. A remote user can invoke these operations without the required app permission to modify customers and create orders without app permission.


Remediation

Install update from vendor's website.