VDB
Sign up
HIGH8.3

GHSA-27wp-jvhw-v4xp

Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

Quick fix

GHSA-27wp-jvhw-v4xp — shopware/core: upgrade to the fixed version with the command below.

composer require shopware/core:^6.5.8.13

Details

### Impact

Shopware has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. It accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code.

### Patches Update to Shopware 6.6.5.1 or 6.5.8.13

### Workarounds For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shopware/core
Introduced in: 0Fixed in: 6.5.8.13
Fixcomposer require shopware/core:^6.5.8.13
Packagist/shopware/platform
Introduced in: 0Fixed in: 6.5.8.13
Fixcomposer require shopware/platform:^6.5.8.13
Packagist/shopware/platform
Introduced in: 6.6.0.0Fixed in: 6.6.5.1
Fixcomposer require shopware/platform:^6.6.5.1
Packagist/shopware/core
Introduced in: 6.6.0.0Fixed in: 6.6.5.1
Fixcomposer require shopware/core:^6.6.5.1

References