Lucene search

K
osvGoogleOSV:GHSA-7GM7-8Q8V-9GF2
HistoryApr 22, 2022 - 9:04 p.m.

Server-Side Request Forgery (SSRF) in Shopware

2022-04-2221:04:07
Google
osv.dev
9

0.001 Low

EPSS

Percentile

42.3%

Impact

The attacker can abuse the Admin SDK functionality on the server to read or update internal resources.

Patches

We recommend updating to the current version 6.4.10.1. You can get the update to 6.4.10.1 regularly via the Auto-Updater or directly via the download overview.

https://www.shopware.com/en/download/#shopware-6

Workarounds

For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

0.001 Low

EPSS

Percentile

42.3%

Related for OSV:GHSA-7GM7-8Q8V-9GF2