CVE-2024-22408: Server-Side Request Forgery (SSRF) in Shopware Flow Builder
Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating the “call webhook” action. This enables malicious users to perform web requests to internal hosts. This issue has been fixed in the Commercial Plugin release 6.5.7.4 or with the Security Plugin. For installations with Shopware 6.4 the Security plugin is recommended to be installed and up to date. For older versions of 6.4 and 6.5 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Shopware Flow Builder (call webhook SSRF fix via plugin)to a version that resolves this vulnerability.Fixed in 6.5.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22408?
CVE-2024-22408 is classified as a high severity vulnerability due to its potential for internal host attacks.
How do I fix CVE-2024-22408?
To fix CVE-2024-22408, upgrade to Shopware version 6.5.7.4 or later where the URL validation issue has been addressed.
What types of attacks can CVE-2024-22408 facilitate?
CVE-2024-22408 can facilitate web requests to internal hosts, potentially leading to unauthorized access or data leakage.
Which versions of Shopware are affected by CVE-2024-22408?
CVE-2024-22408 affects versions of Shopware earlier than 6.5.7.4.
How does CVE-2024-22408 impact the security of Shopware applications?
CVE-2024-22408 compromises the security of Shopware applications by allowing malicious users to exploit inadequate URL validation in webhooks.