VDB
Sign up
HIGH7.2

GHSA-7cw6-7h3h-v8pf

Shopware Has Improper Control of Generation of Code in Twig rendered views

Quick fix

GHSA-7cw6-7h3h-v8pf — shopware/shopware: upgrade to the fixed version with the command below.

composer require shopware/shopware:^6.7.6.1

Details

### Impact We fixed with [CVE-2023-2017](https://github.com/advisories/GHSA-7v2v-9rm4-7m8f) Twig filters to only be executed with allowed functions. However there was a regression that lead to an array and array crafted PHP Closure not checked being against allow list for the map(...) override

### Patches Patched in 6.7.6.1

### Workarounds Install the security plugin

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shopware/shopware
Introduced in: 6.7.0.0Fixed in: 6.7.6.1
Fixcomposer require shopware/shopware:^6.7.6.1
Packagist/shopware/core
Introduced in: 6.7.0.0Fixed in: 6.7.6.1
Fixcomposer require shopware/core:^6.7.6.1

References