Exposure of Sensitive Information to an Unauthorized Actor
Moderate severity
GitHub Reviewed
Published
Sep 8, 2021
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jun 24, 2021
Reviewed
Jun 25, 2021
Published to the GitHub Advisory Database
Sep 8, 2021
Last updated
Jan 29, 2023
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
References