{"id":"GHSA-q3g4-2vw9-xv27","aliases":[],"url":"https://o3.security/vulnerability/GHSA-q3g4-2vw9-xv27","summary":"Shopware Remote Code Execution Vulnerability","details":"Under certain circumstances, it’s possible to execute an unauthorized foreign code in Shopware. This is a critical security vulnerability that could affect the entire system. All Shopware versions including Shopware 5.2.14 are affected.\n","published":"2024-05-21T18:50:07Z","modified":"2024-12-06T05:38:17.931613Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"shopware/shopware","fixedVersion":"5.2.15"},{"ecosystem":"Packagist","name":"shopware/shopware","fixedVersion":"1.0.8"}],"fix":{"url":"https://github.com/shopware5/shopware/commit/14299e9ee9f7d93f687b4ec838e0873afbc84fec","label":"shopware5/shopware@14299e9"},"references":[{"type":"WEB","url":"https://github.com/shopware5/shopware/commit/14299e9ee9f7d93f687b4ec838e0873afbc84fec"},{"type":"WEB","url":"https://community.shopware.com/_detail_1989.html"},{"type":"WEB","url":"https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-01-2017?category=shopware-5-en/security-updates"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/shopware/shopware/2017-01-24.yaml"},{"type":"PACKAGE","url":"https://github.com/shopware5/shopware"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:38:17.931613Z"}}