CVE-2022-21652

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-21652
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-21652.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-21652
Aliases
Published
2022-01-05T19:20:18Z
Modified
2025-10-13T04:36:20Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Insufficient Session Expiration in shopware
Details

Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_versions

[
    {
        "type": "",
        "events": [
            {
                "introduced": "5.7.3"
            },
            {
                "fixed": "5.7.7"
            }
        ]
    }
]

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-21652.json"