Dependency configuration exposed in Shopware
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the specific Shopware version in a deployment might be determined by an attacker, which could be used for further attacks. Users are advised to update to version 5.7.18. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
shopware · shopwareReferences
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2023https://github.com/shopware5/shopware/commit/b3518c8d9562a38615d638f31f79829f6e2f4b6ahttps://github.com/shopware/shopware/security/advisories/GHSA-q97c-2mh3-pgw9https://www.shopware.com/en/changelog-sw5/#5-7-18