
Cloud Vulnerability DB
A community-led vulnerabilities database
An authenticated Server-Side Request Forgery (SSRF) vulnerability was identified in Shopware, affecting both shopware/core and shopware/platform Composer packages versions 6.3.4.0 and earlier. The vulnerability was disclosed on December 15, 2020, and was assigned the identifier GHSA-8pfh-mm2g-hmc3. This security issue was discovered by REQON B.V. and was given a low severity rating (GitHub Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and received a low severity assessment. No CVE identifier was assigned to this vulnerability. The issue affects the Shopware e-commerce platform, specifically impacting versions up to and including 6.3.4.0 of both shopware/core and shopware/platform packages (GitHub Advisory).
The vulnerability allows authenticated users to perform Server-Side Request Forgery attacks against the affected Shopware installations. Given the low severity rating and the requirement for authentication, the potential impact appears to be limited (GitHub Advisory).
The vulnerability requires authentication to exploit, which significantly reduces its exploitability in the wild. No public exploits or active exploitation have been reported (GitHub Advisory).
The vulnerability has been patched in version 6.3.4.1 of both affected packages. Users are recommended to update to this version through the Auto-Updater or via the download overview. For older versions (6.1 and 6.2), a plugin-based fix is available through the Shopware store. Detailed information about the security update can be found in Shopware's security documentation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."