Sensitive information sent insecurely In shopware/storefront
Description
HTTP caching is marking private HTTP headers as public in Shopware
Impact
HTTP caching is marking private HTTP headers as public
Patches
Fixed in recommend updating to the current version 6.4.8.2. You can get the update to 6.4.8.2 regularly via the Auto-Updater or directly via the download overview.
https://www.shopware.com/en/download/#shopware-6
Workarounds
For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 6.4.8.2 | ||
packagist | 6.4.8.2 | ||
packagist | 6.4.8.2 |
Aliases
References