The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time.
We added an automatic logout into the Administration, so the user will be logged out when they are inactive.
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
{ "nvd_published_at": "2023-01-17T22:15:00Z", "github_reviewed_at": "2023-01-20T23:18:17Z", "severity": "LOW", "github_reviewed": true, "cwe_ids": [ "CWE-613" ] }