VDB
Sign up
HIGH7.5

GHSA-r4ph-mx67-x58p

Shopware database password is leaked to an unauthenticated users

Quick fix

GHSA-r4ph-mx67-x58p — shopware/core: upgrade to the fixed version with the command below.

composer require shopware/core:^6.2.3

Details

In Shopware 6 before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled. This vulnerability does not affect the shopware 5 release branch (`shopware/shopware` on packagist).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shopware/core
Introduced in: 6.0.0Fixed in: 6.2.3
Fixcomposer require shopware/core:^6.2.3
Packagist/shopware/platform
Introduced in: 6.0.0Fixed in: 6.2.3
Fixcomposer require shopware/platform:^6.2.3

References