VDB
Sign up
LOW3.7

GHSA-59qg-93jg-236f

Shopware has Insufficient Session Expiration in Administration

Quick fix

GHSA-59qg-93jg-236f — shopware/platform: upgrade to the fixed version with the command below.

composer require shopware/platform:^6.4.18.1

Details

### Impact The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time.

### Patches We added an automatic logout into the Administration, so the user will be logged out when they are inactive.

### References

https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shopware/platform
Introduced in: 0Fixed in: 6.4.18.1
Fixcomposer require shopware/platform:^6.4.18.1
Packagist/shopware/core
Introduced in: 0Fixed in: 6.4.18.1
Fixcomposer require shopware/core:^6.4.18.1

References