Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32717

Опубликовано: 24 июн. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as type. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command ./bin/console s3:set-visibility to correct your cloud file visibilities.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*
Версия от 6.1.0 (включая) до 6.4.1.1 (исключая)

EPSS

Процентиль: 56%
0.0033
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-732

Связанные уязвимости

CVSS3: 7.5
github
больше 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor

EPSS

Процентиль: 56%
0.0033
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-732