Skip to content

Authenticated Privilege Escalation

Low
pweyck published GHSA-5q58-x5h2-v5rx Dec 15, 2020

Package

composer shopware/platform,shopware/core (Composer)

Affected versions

<= 6.3.4.0

Patched versions

6.3.4.1

Description

Impact

Authenticated Privilege Escalation

Patches

We recommend to update to the current version 6.3.4.1. You can get the update to 6.3.4.1 regularly via the Auto-Updater or directly via the download overview.

https://www.shopware.com/en/download/#shopware-6

Workarounds

For older versions of 6.1 and 6.2 the corresponding changes are also available via plugin:

https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659

For more information

https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-12-2020

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs