Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-83vp-6jqg-6cmr

Опубликовано: 10 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Incorrect Authentication in shopware

Impact

Modify Customers, create Orders without App Permission

Patches

We recommend updating to the current version 6.4.8.2. You can get the update to 6.4.8.2 regularly via the Auto-Updater or directly via the download overview.

https://www.shopware.com/en/download/#shopware-6

Workarounds

For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Пакеты

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

<= 6.4.8.1

6.4.8.2

EPSS

Процентиль: 45%
0.00222
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-287
CWE-863

Связанные уязвимости

CVSS3: 6.8
nvd
почти 4 года назад

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper api route checking. Users are advised to upgrade to version 6.4.8.2. There are no known workarounds.

EPSS

Процентиль: 45%
0.00222
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-287
CWE-863