PT-2024-29890 · Shopware · Shopware
Joshuabehrens
·
Published
2024-08-08
·
Updated
2024-08-12
·
CVE-2024-42354
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 6.6.5.1
Shopware versions prior to 6.5.8.13
Description
The issue is related to the store-API, which works with regular entities and only exposes fields marked as ApiAware in the EntityDefinition to the public API. However, prior to certain versions, the processing of the Criteria did not consider ManyToMany associations, which could lead to improper consideration and failure of protections. This issue cannot be reproduced with default entities but can be triggered with extensions.
Recommendations
Update to Shopware 6.6.5.1 to receive a patch.
Update to Shopware 6.5.8.13 to receive a patch.
For older versions of 6.2, 6.3, and 6.4, install the corresponding security plugin to apply security measures.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopware