CVE-2025-22386

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:*

History

20 May 2025, 20:12

Type Values Removed Values Added
First Time Optimizely configured Commerce
Optimizely
CPE cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:*
References () https://support.optimizely.com/hc/en-us/articles/32695284701069-Configured-Commerce-Security-Advisory-COM-2024-04 - () https://support.optimizely.com/hc/en-us/articles/32695284701069-Configured-Commerce-Security-Advisory-COM-2024-04 - Vendor Advisory
Summary
  • (es) Se descubrió un problema en Optimizely Configured Commerce antes de la versión 5.2.2408. Existe un problema de sesión de gravedad media en la aplicación Commerce B2B, que afecta la longevidad de las sesiones activas en la tienda. Esto permite que los tokens de sesión vinculados a sesiones cerradas sigan activos y se puedan usar.

06 Jan 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

04 Jan 2025, 03:15

Type Values Removed Values Added
CWE CWE-613

04 Jan 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-04 02:15

Updated : 2025-05-20 20:12


NVD link : CVE-2025-22386

Mitre link : CVE-2025-22386

CVE.ORG link : CVE-2025-22386


JSON object : View

Products Affected

optimizely

  • configured_commerce
CWE
CWE-613

Insufficient Session Expiration