Skip to content

Broken Access Control order API

Moderate
pweyck published GHSA-3867-jc5c-66qf Jan 16, 2024

Package

composer shopware/core (Composer)

Affected versions

<= 6.5.7.3

Patched versions

6.5.7.4
composer shopware/platform (Composer)
<= 6.5.7.3
6.5.7.4

Description

Impact

In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations
for actions that modify the payment, delivery, and/or order status. Due to this inadequate
implementation, users lacking 'write' permissions for orders are still able to change the order
state.

Patches

Update to Shopware 6.5.7.4

Workarounds

For older versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Severity

Moderate
4.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CVE ID

CVE-2024-22407

Weaknesses