Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-24748: Build software better, together

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper api route checking. Users are advised to upgrade to version 6.4.8.2. There are no known workarounds.

CVE
#java

Modify Customers, create Orders without App Permission

Package

composer shopware/core (Composer)

Affected versions

<= 6.3.1.0

Description

Impact

Modify Customers, create Orders without App Permission

Patches

We recommend updating to the current version 6.4.8.2. You can get the update to 6.4.8.2 regularly via the Auto-Updater or directly via the download overview.

https://www.shopware.com/en/download/#shopware-6

Workarounds

For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

CVE ID

CVE-2022-24748

GHSA ID

GHSA-83vp-6jqg-6cmr

CWEs

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907