Medium severity6.3NVD Advisory· Published Mar 9, 2022· Updated Jun 17, 2026
CVE-2022-24747
CVE-2022-24747
Description
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and client then headers may be exposed via HTTP caches. This issue has been resolved in version 6.4.8.2. There are no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/platformPackagist | < 6.4.8.2 | 6.4.8.2 |
shopware/corePackagist | < 6.4.8.2 | 6.4.8.2 |
shopware/storefrontPackagist | < 6.4.8.2 | 6.4.8.2 |
Affected products
5- shopware/platformv5Range: < 6.4.8.2
- ghsa-coords3 versions
< 6.4.8.2+ 2 more
- (no CPE)range: < 6.4.8.2
- (no CPE)range: < 6.4.8.2
- (no CPE)range: < 6.4.8.2
Patches
Vulnerability mechanics
References
5- docs.shopware.com/en/shopware-6-en/security-updates/security-update-03-2022nvdPatchVendor AdvisoryWEB
- github.com/shopware/platform/commit/d51863148f32306aafdbc7f9f48887c69fce206fnvdPatchThird Party AdvisoryWEB
- github.com/shopware/platform/security/advisories/GHSA-6wrh-279j-6hvwnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6wrh-279j-6hvwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24747ghsaADVISORY
News mentions
0No linked articles in our index yet.