Lack of data validation In shopware/core

Description

RCE in Third Party Library in Shopware

Impact

RCE in Third Party Library

Patches

We recommend to update to the current version 6.3.1.1. You can get the update to 6.3.1.1 regularly via the Auto-Updater or directly via the download overview.

For older versions you can use the Security Plugin: https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659

References

https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-09-2020

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions