PT-2024-19398 · Shopware · Shopware
Pweyck
·
Published
2024-01-16
·
Updated
2024-01-24
·
CVE-2024-22408
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 6.5.7.4
Shopware version 6.4
Description
The Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requests to internal hosts.
Recommendations
For versions prior to 6.5.7.4, update to the Commercial Plugin release 6.5.7.4 or install the Security Plugin.
For version 6.4, ensure the Security plugin is installed and up to date.
For older versions of 6.4 and 6.5, corresponding security measures are available via a plugin.
As a temporary workaround, consider restricting the use of the Flow Builder functionality until a patch is available.
For the full range of functions, update to the latest Shopware version.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopware