Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27wp-jvhw-v4xp

Опубликовано: 08 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.3

Описание

Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

Impact

Shopware has a new Twig Tag sw_silent_feature_call which silences deprecation messages while triggered in this tag. It accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code.

Patches

Update to Shopware 6.6.5.1 or 6.5.8.13

Workarounds

For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Пакеты

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

<= 6.5.8.12

6.5.8.13

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

<= 6.5.8.12

6.5.8.13

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

>= 6.6.0.0, <= 6.6.5.0

6.6.5.1

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

>= 6.6.0.0, <= 6.6.5.0

6.6.5.1

EPSS

Процентиль: 73%
0.00777
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-1336
CWE-94

Связанные уязвимости

CVSS3: 8.3
nvd
больше 1 года назад

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin.

EPSS

Процентиль: 73%
0.00777
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-1336
CWE-94