The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time.
We added an automatic logout into the Administration, so the user will be logged out when they are inactive.
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
{
"cwe_ids": [
"CWE-613"
],
"github_reviewed": true,
"nvd_published_at": "2023-01-17T22:15:00Z",
"severity": "LOW",
"github_reviewed_at": "2023-01-20T23:18:17Z"
}