Shopware dependency configuration exposed
Moderate severity
GitHub Reviewed
Published
Jun 27, 2023
in
shopware5/shopware
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
Jun 27, 2023
Published to the GitHub Advisory Database
Jun 28, 2023
Reviewed
Jun 28, 2023
Last updated
Nov 10, 2023
Impact
Due to a wrong configuration in the
.htaccess
file, the configuration file of Javascript dependencies could be read in production environments (themes/package-lock.json
). With this information, the used Shopware version might be determined by an attacker, which could be used for further attacks.Patches
We recommend updating to the current version 5.7.18. You can get the update to 5.7.18 regularly via the Auto-Updater or directly via the release page.
https://github.com/shopware5/shopware/releases/tag/v5.7.18
For older versions you can use the Security Plugin:
https://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html
References
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2023
References