MEDIUM5.3
GHSA-5297-wrrp-rcj7
Shopware Improper Session Handling in store-api account logout
Quick fix
GHSA-5297-wrrp-rcj7 — shopware/core: upgrade to the fixed version with the command below.
composer require shopware/core:^6.5.8.8Details
### Impact
When a authentificated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on `CustomerLogoutEvent` and invalidates the session additionally.
### Patches The problem has been fixed with Shopware 6.6.1.0 and 6.5.8.8.
### Workarounds When you are not able to update, you can install the latest version of the Shopware Security Plugin.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/shopware/core
Introduced in:
6.3.5.0Fixed in: 6.5.8.8Fix
composer require shopware/core:^6.5.8.8Packagist/shopware/platform
Introduced in:
6.3.5.0Fixed in: 6.5.8.8Fix
composer require shopware/platform:^6.5.8.8Packagist/shopware/core
Introduced in:
6.6.0.0-rc1Fixed in: 6.6.1.0Fix
composer require shopware/core:^6.6.1.0Packagist/shopware/platform
Introduced in:
6.6.0.0-rc1Fixed in: 6.6.1.0Fix
composer require shopware/platform:^6.6.1.0References
- https://github.com/shopware/shopware/security/advisories/GHSA-5297-wrrp-rcj7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-31447[ADVISORY]
- https://github.com/shopware/shopware/commit/5cc84ddd817ad0c1d07f9b3c79ab346d50514a77[WEB]
- https://github.com/shopware/shopware/commit/d29775aa758f70d08e0c5999795c7c26d230e7d3[WEB]
- https://github.com/shopware/shopware[PACKAGE]