SB2022030940 - Multiple vulnerabilities in Shopware
Published: March 9, 2022 Updated: May 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2022-24745)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access another customer's guest session data.
The vulnerability exists due to improper access control in the guest session handling logic when HTTP cache is enabled. A remote attacker can send requests that reuse a shared guest session to access another customer's guest session data.
Only installations with HTTP cache enabled are vulnerable. Setups using Varnish are not affected.
2) Improper access control (CVE-ID: CVE-2022-24747)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in HTTP caching when handling cached HTTP headers. A remote attacker can trigger caching of private HTTP headers to disclose sensitive information.
3) Improper access control (CVE-ID: CVE-2022-24748)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify customers and create orders without app permission.
The vulnerability exists due to improper access control in app permission enforcement when handling customer modification and order creation operations. A remote user can invoke these operations without the required app permission to modify customers and create orders without app permission.
Remediation
Install update from vendor's website.
References
- https://github.com/shopware/shopware/security/advisories/GHSA-jp6h-mxhx-pgqh
- https://github.com/shopware/shopware/security/advisories/GHSA-6wrh-279j-6hvw
- https://github.com/advisories/GHSA-6wrh-279j-6hvw
- https://github.com/shopware/shopware/security/advisories/GHSA-83vp-6jqg-6cmr
- https://github.com/advisories/GHSA-83vp-6jqg-6cmr