CVE-2024-42355: high-severity vulnerability in shopware
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.3epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected products
shopware · shopwareRelated CVEs — shopware
In the same product, most dangerous first.
CVE-2021-32712MEDIUMInformation leakage in Error HandlerEPSS 1.1%CVE-2022-24892MEDIUMMultiple valid tokens for password reset in ShopwareEPSS 0.9%CVE-2022-36102MEDIUMAcess control list bypassed via crafted specific URLsEPSS 0.8%CVE-2022-21652LOWInsufficient Session Expiration in shopwareEPSS 0.8%CVE-2022-24873MEDIUMNon-Stored Cross-site Scripting in Shopware storefrontEPSS 0.8%CVE-2022-21651MEDIUMOpen redirect in shopwareEPSS 0.8%
References
https://github.com/shopware/core/commit/a784aa1cec0624e36e0ee4d41aeebaed40e0442fhttps://github.com/shopware/core/commit/d35ee2eda5c995faeb08b3dad127eab65c64e2a2https://github.com/shopware/shopware/commit/445c6763cc093fbd651e0efaa4150deae4ae60dahttps://github.com/shopware/shopware/commit/8504ba7e56e53add6a1d5b9d45015e3d899cd0achttps://github.com/shopware/shopware/security/advisories/GHSA-27wp-jvhw-v4xp