HIGH
Server-Side Request Forgery (SSRF) in Shopware
Published Apr 20, 2022
7.2
HIGHCVSS 3.1
EPSS 1.06%
Description
Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.
Affected products
-
- Version < 6.4.10.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-04-2022 x_refsource_MISCPatchThird Party Advisory
- https://github.com/advisories/GHSA-7gm7-8q8v-9gf2 Advisory
- https://github.com/shopware/platform/commit/083765e2d64a00315050c4891800c9e98ba0c77c x_refsource_MISCPatchThird Party Advisory
- https://github.com/shopware/platform/security/advisories/GHSA-7gm7-8q8v-9gf2 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-24871
| Link | Providers | Tags |
|---|---|---|
| https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-04-2022 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-7gm7-8q8v-9gf2 | Advisory | |
| https://github.com/shopware/platform/commit/083765e2d64a00315050c4891800c9e98ba0c77c | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/shopware/platform/security/advisories/GHSA-7gm7-8q8v-9gf2 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-24871 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 20, 2022
Updated Apr 23, 2025
Reserved Feb 10, 2022
Link CVE-2022-24871
CISA Vulnrichment
GHSA-7GM7-8Q8V-9GF2 Updated Apr 23, 2025