PT-2021-19877 · Shopware · Shopware

Phil23

·

Published

2021-02-10

·

Updated

2026-03-12

·

CVE-2021-32711

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 6.3.5.1
Description The issue is related to a leak of information via the Store-API. This could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations To resolve the issue, update to the current version 6.3.5.1. This update can be obtained regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1 and 6.2, corresponding security measures are also available via a plugin. It is recommended to check plugins for usage and update to the latest Shopware version for the full range of functions. As a temporary workaround, consider reviewing and restricting the use of the Store-API until the update is applied.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-32711
GHSA-2P89-5F22-8QVF
GHSA-F2VV-H5X4-57GR

Affected Products

Shopware