Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0yN3dwLWp2aHctdjR4cM4AA-f-
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
Impact
Shopware has a new Twig Tag sw_silent_feature_call
which silences deprecation messages while triggered in this tag.
It accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code.
Patches
Update to Shopware 6.6.5.1 or 6.5.8.13
Workarounds
For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Permalink: https://github.com/advisories/GHSA-27wp-jvhw-v4xpJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yN3dwLWp2aHctdjR4cM4AA-f-
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 1 month ago
Updated: 30 days ago
CVSS Score: 8.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Identifiers: GHSA-27wp-jvhw-v4xp, CVE-2024-42355
References:
- https://github.com/shopware/shopware/security/advisories/GHSA-27wp-jvhw-v4xp
- https://github.com/shopware/core/commit/a784aa1cec0624e36e0ee4d41aeebaed40e0442f
- https://github.com/shopware/core/commit/d35ee2eda5c995faeb08b3dad127eab65c64e2a2
- https://github.com/shopware/shopware/commit/445c6763cc093fbd651e0efaa4150deae4ae60da
- https://github.com/shopware/shopware/commit/8504ba7e56e53add6a1d5b9d45015e3d899cd0ac
- https://nvd.nist.gov/vuln/detail/CVE-2024-42355
- https://github.com/advisories/GHSA-27wp-jvhw-v4xp
Blast Radius: 20.5
Affected Packages
packagist:shopware/core
Dependent packages: 216Dependent repositories: 298
Downloads: 2,947,360 total
Affected Version Ranges: >= 6.6.0.0, <= 6.6.5.0, <= 6.5.8.12
Fixed in: 6.6.5.1, 6.5.8.13
All affected versions: 6.0.0, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.2.0, 6.2.1, 6.2.2, 6.2.3
All unaffected versions:
packagist:shopware/platform
Dependent packages: 6Dependent repositories: 38
Downloads: 1,210,388 total
Affected Version Ranges: >= 6.6.0.0, <= 6.6.5.0, <= 6.5.8.12
Fixed in: 6.6.5.1, 6.5.8.13
All affected versions: 5.3.1, 6.0.0, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.2.0, 6.2.1, 6.2.2, 6.2.3
All unaffected versions: