shopware/core Security Advisories for v6.6.0.0-rc7 (5)
-
[HIGH] Shopware vulnerable to blind SQL-injection in DAL aggregations
PKSA-wp2c-7yp8-5fvs CVE-2024-42357 GHSA-p6w9-r443-r752
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub -
[HIGH] Shopware vulnerable to Server Side Template Injection in Twig using Context functions
PKSA-kt1g-n1g2-hzb4 CVE-2024-42356 GHSA-35jp-8cgg-p4wj
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub -
[HIGH] Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
PKSA-6stq-czfs-1nvv CVE-2024-42355 GHSA-27wp-jvhw-v4xp
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub -
[MEDIUM] Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api
PKSA-4spx-rq41-wk8h CVE-2024-42354 GHSA-hhcq-ph6w-494g
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub -
[MEDIUM] Shopware Improper Session Handling in store-api account logout
PKSA-s8vz-878v-gv1c CVE-2024-31447 GHSA-5297-wrrp-rcj7
Affected version: >=6.6.0.0-rc1,<6.6.1.0|>=6.3.5.0,<6.5.8.8
Reported by:
GitHub