First published: Thu Jun 24 2021(Updated: )
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopware Shopware | >=6.1.0<6.4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32716 is a vulnerability in the admin API of Shopware eCommerce platform versions prior to 6.4.1.1.
CVE-2021-32716 has a severity level of medium with a CVSS score of 4.9.
CVE-2021-32716 exposes internal hidden fields in the Shopware admin API when a specific association is loaded with a to-many reference.
To fix CVE-2021-32716, users of Shopware eCommerce platform should update to version 6.4.1.1 or later.
You can find more information about CVE-2021-32716 from the official Shopware documentation and the GitHub security advisories.