{"id":"GHSA-68wv-g3fw-pq7q","aliases":[],"url":"https://o3.security/vulnerability/GHSA-68wv-g3fw-pq7q","summary":"Shopware Broken ACL on Document retrieval to access other customers documents","details":"### Impact\nIt's possible to guess the deepLinkCode of an Document to open documents of other customers\n\n### Patches\nUpdate to Shopware 6.6.10.3 or 6.5.8.17\n\n### Workarounds\nFor older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.","published":"2025-04-08T16:33:30Z","modified":"2025-04-08T16:37:25.476986Z","cvss":{"score":4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"shopware/core","fixedVersion":"6.6.10.3"},{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":"6.6.10.3"},{"ecosystem":"Packagist","name":"shopware/core","fixedVersion":"6.7.0.0-rc2"},{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":"6.7.0.0-rc2"},{"ecosystem":"Packagist","name":"shopware/core","fixedVersion":"6.5.8.17"},{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":"6.5.8.17"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/shopware/shopware/security/advisories/GHSA-68wv-g3fw-pq7q"},{"type":"PACKAGE","url":"https://github.com/shopware/shopware"},{"type":"WEB","url":"https://github.com/shopware/shopware/releases/tag/v6.5.8.17"},{"type":"WEB","url":"https://github.com/shopware/shopware/releases/tag/v6.6.10.3"},{"type":"WEB","url":"https://github.com/shopware/shopware/releases/tag/v6.7.0.0-rc2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-08T16:37:25.476986Z"}}