Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cp7-jfp6-jh4f

Опубликовано: 20 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 2.7

Описание

Shopware's log module vulnerable to Improper Output Neutralization

Impact

The log module contains all kind of sent mails. It is possible to see the password reset email of customers and admin users to gain probably more access.

Patches

Update to the latest 6.4.18.1 version.

Workarounds

  • For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
  • Remove from all users the log module ACL rights
  • Disable logging

References

https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates

Пакеты

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

<= 6.4.18.0

6.4.18.1

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

<= 6.4.18.0

6.4.18.1

EPSS

Процентиль: 53%
0.003
Низкий

2.7 Low

CVSS3

Дефекты

CWE-117
CWE-532

Связанные уязвимости

CVSS3: 2.7
nvd
около 3 лет назад

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may have access to other users accounts. This issue has been addressed in version 6.4.18.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. Users unable to upgrade may remove from all users the log module ACL rights or disable logging.

EPSS

Процентиль: 53%
0.003
Низкий

2.7 Low

CVSS3

Дефекты

CWE-117
CWE-532