Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gr8-c3m5-mvrg

Опубликовано: 08 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Exposure of Sensitive Information to an Unauthorized Actor

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as type. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command ./bin/console s3:set-visibility to correct your cloud file visibilities.

Пакеты

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

<= 6.4.1.0

6.4.1.1

EPSS

Процентиль: 55%
0.0033
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-732

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command `./bin/console s3:set-visibility` to correct your cloud file visibilities.

EPSS

Процентиль: 55%
0.0033
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-732