Improper authorization control for web services In shopware/platform
Description
Shopware Broken ACL on Document retrieval to access other customers documents
Impact
It's possible to guess the deepLinkCode of an Document to open documents of other customers
Patches
Update to Shopware 6.6.10.3 or 6.5.8.17
Workarounds
For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 6.6.10.3, 6.7.0.0-rc2, 6.5.8.17 | ||
packagist | 6.6.10.3, 6.7.0.0-rc2, 6.5.8.17 |
Aliases
1. 2.
References
1. 2. 3. 4.