CVE-2021-32716: Internal hidden fields are visible on to many associations in admin api
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-32716?
CVE-2021-32716 is a vulnerability in the admin API of Shopware eCommerce platform versions prior to 6.4.1.1.
What is the severity of CVE-2021-32716?
CVE-2021-32716 has a severity level of medium with a CVSS score of 4.9.
How does CVE-2021-32716 affect Shopware?
CVE-2021-32716 exposes internal hidden fields in the Shopware admin API when a specific association is loaded with a to-many reference.
How can I fix CVE-2021-32716?
To fix CVE-2021-32716, users of Shopware eCommerce platform should update to version 6.4.1.1 or later.
Where can I find more information about CVE-2021-32716?
You can find more information about CVE-2021-32716 from the official Shopware documentation and the GitHub security advisories.