SCA: security update for shopware/platform, shopware/storefront (GHSA-c2f9-4jmm-v45m)

high Tenable Self-Hosted Container Security Plugin ID 413579

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops
the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to
improve the performance of 404 pages. So the cached Response which contains a Session Cookie when the
Browser accessing the 404 page, has no cookies yet. The Symfony Session Handler is in use, when no
explicit Session configuration has been done. When Redis is in use for Sessions using the PHP Redis
extension, this exploiting code is not used. Shopware version 6.5.8.7 contains a patch for this issue. As
a workaround, use Redis for Sessions, as this does not trigger the exploit code. (CVE-2024-27917)

See Also

https://github.com/advisories/GHSA-c2f9-4jmm-v45m

Plugin Details

Severity: High

ID: 413579

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2024-27917

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/6/2024

Vulnerability Publication Date: 3/6/2024

Reference Information

CVE: CVE-2024-27917

cwe: CWE-524