CVE-2021-32716Sensitive Information Exposure in Platform

Severity
4.9MEDIUMNVD
EPSS
0.3%
top 45.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 24
Latest updateSep 8

Description

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages3 packages

CVEListV5shopware/platform< 6.4.1.1
Packagistshopware/platform< 6.4.1.1
NVDshopware/shopware6.1.06.4.1.1

Patches

🔴Vulnerability Details

2
GHSA
Exposure of Sensitive Information to an Unauthorized Actor2021-09-08
OSV
Exposure of Sensitive Information to an Unauthorized Actor2021-09-08