Due to a wrong configuration in the .htaccess
file, the configuration file of Javascript dependencies could be read in production environments (themes/package-lock.json
). With this information, the used Shopware version might be determined by an attacker, which could be used for further attacks.
We recommend updating to the current version 5.7.18. You can get the update to 5.7.18 regularly via the Auto-Updater or directly via the release page. https://github.com/shopware5/shopware/releases/tag/v5.7.18
For older versions you can use the Security Plugin: https://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2023
{ "nvd_published_at": "2023-06-27T17:15:09Z", "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-06-28T22:33:26Z" }