
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical vulnerability (CVE-2021-32711) was discovered in Shopware, an open source eCommerce platform, affecting versions prior to 6.3.5.1. The vulnerability involves information leakage via the Store-API. The issue was disclosed on February 8, 2021, and affects all Shopware versions from 6.1.0 up to and including 6.3.5.0 (GitHub Advisory, Shopware Docs).
The vulnerability received a CVSS v3.1 base score of 9.1 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) from GitHub, and 7.5 HIGH from NVD. The issue is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change affecting Store-API consumers (NVD).
The vulnerability allows unauthorized access to sensitive information through the Store-API. The critical severity rating and high CVSS scores indicate that this information leak could potentially expose confidential data to unauthorized actors (GitHub Advisory).
The vulnerability is remotely exploitable with low attack complexity and requires no privileges or user interaction. The CVSS metrics indicate that an attacker can exploit this vulnerability over the network without requiring any special conditions or user involvement (NVD).
The primary mitigation is to update to version 6.3.5.1. For older versions (6.1 and 6.2), security measures are available via a plugin, though updating to the latest version is recommended for full functionality. The update can be obtained through the Auto-Updater or directly from the download overview. Users should check their plugins after updating due to the non-backward-compatible API changes (Shopware Docs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."