CVE-2021-32717
published 2021-06-24CVE-2021-32717: Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.46%
70.8th percentile
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command `./bin/console s3:set-visibility` to correct your cloud file visibilities.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopware | platform | < 6.4.1.1 | 6.4.1.1 |
| shopware | platform | >= 0 < 6.4.1.1 | 6.4.1.1 |
| shopware | shopware | >= 6.1.0 < 6.4.1.1 | 6.4.1.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor
osv·2021-09-08
CVE-2021-32717 [HIGH] Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the comman
GHSA
Exposure of Sensitive Information to an Unauthorized Actor
ghsa·2021-09-08
CVE-2021-32717 [HIGH] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the comman
No detection rules found.
No public exploits indexed.
Wiz
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
blogs_wiz·2025-04-09
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
Indicators of compromise (IOCs) signal a potential security breach, acting as digital evidence of suspicious activity within a system or a network. By providing the context that computer security incident response teams (CSIRTs) need, IOCs help businesses neutralize attacks swiftly. This digital forensic data can also come in handy during post-event analysis to pinpoint the root cause of the breach and help teams strategize precautionary measures to prevent similar attacks in the future.
Remember: Threat actors are always improving their techniques—honing the use of automation, diverse attack vectors, artificial intelligence, and sophisticated invasion techniques—to infiltrate software systems undetected and achieve their malicious goals. IBM’s Cost of a Data Breach report from 2024 says
Wiz
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
blogs_wiz·2025-04-09
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
Indicators of compromise (IOCs) signal a potential security breach, acting as digital evidence of suspicious activity within a system or a network. By providing the context that computer security incident response teams ( CSIRTs ) need, IOCs help businesses neutralize attacks swiftly. This digital forensic data can also come in handy during post-event analysis to pinpoint the root cause of the breach and help teams strategize precautionary measures to prevent similar attacks in the future.
Remember: Threat actors are always improving their techniques—honing the use of automation, diverse attack vectors, artificial intelligence, and sophisticated invasion techniques—to infiltrate software systems undetected and achieve their malicious goals. IBM’s Cost of a Data Breach report from 2024 say
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-06-2021https://github.com/shopware/platform/commit/ba52f683372b8417a00e9014f481ed3d539f34b3https://github.com/shopware/platform/security/advisories/GHSA-vrf2-xghr-j52vhttps://docs.shopware.com/en/shopware-6-en/security-updates/security-update-06-2021https://github.com/shopware/platform/commit/ba52f683372b8417a00e9014f481ed3d539f34b3https://github.com/shopware/platform/security/advisories/GHSA-vrf2-xghr-j52v
2021-06-24
Published