Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. shopware/platform
  4. ›
  5. GHSA-c7vg-w8q8-c3wf

GHSA-c7vg-w8q8-c3wf: Duplicate Advisory: Session Fixation

September 8, 2021 (updated February 2, 2026)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-h9q8-5gv2-v6mg. This link is maintained to preserve external references.

Original Description

Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1 and 6.2, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

References

  • github.com/advisories/GHSA-c7vg-w8q8-c3wf
  • github.com/shopware/platform/commit/010c0154bea57c1fca73277c7431d029db7a972e
  • github.com/shopware/platform/security/advisories/GHSA-h9q8-5gv2-v6mg
  • nvd.nist.gov/vuln/detail/CVE-2021-32710

Code Behaviors & Features

Detect and mitigate GHSA-c7vg-w8q8-c3wf with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 6.3.5.2

Fixed versions

  • 6.3.5.2

Solution

Upgrade to version 6.3.5.2 or above.

Impact 5.9 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-384: Session Fixation

Source file

packagist/shopware/platform/GHSA-c7vg-w8q8-c3wf.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:35:14 +0000.