GHSA-q97c-2mh3-pgw9

Suggest an improvement
Source
https://github.com/advisories/GHSA-q97c-2mh3-pgw9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-q97c-2mh3-pgw9/GHSA-q97c-2mh3-pgw9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q97c-2mh3-pgw9
Aliases
  • CVE-2023-34098
Published
2023-06-28T22:33:26Z
Modified
2024-02-16T08:04:21.043099Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Shopware dependency configuration exposed
Details

Impact

Due to a wrong configuration in the .htaccess file, the configuration file of Javascript dependencies could be read in production environments (themes/package-lock.json). With this information, the used Shopware version might be determined by an attacker, which could be used for further attacks.

Patches

We recommend updating to the current version 5.7.18. You can get the update to 5.7.18 regularly via the Auto-Updater or directly via the release page. https://github.com/shopware5/shopware/releases/tag/v5.7.18

For older versions you can use the Security Plugin: https://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html

References

https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2023

Database specific
{
    "nvd_published_at": "2023-06-27T17:15:09Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-06-28T22:33:26Z"
}
References

Affected packages

Packagist / shopware/shopware

Package

Name
shopware/shopware
Purl
pkg:composer/shopware/shopware

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.7.18

Affected versions

v5.*

v5.6.0
v5.6.1
v5.6.2
v5.6.3
v5.6.4
v5.6.5
v5.6.6
v5.6.7
v5.6.8
v5.6.9
v5.6.10
v5.7.0-RC1
v5.7.0-RC2
v5.7.0
v5.7.1
v5.7.2
v5.7.3
v5.7.4
v5.7.5
v5.7.6
v5.7.7
v5.7.8
v5.7.9
v5.7.10
v5.7.11
v5.7.12
v5.7.13
v5.7.14
v5.7.15
v5.7.16-RC1
v5.7.16
v5.7.17-RC1
v5.7.17

Database specific

{
    "last_known_affected_version_range": "<= 5.7.17"
}