SCA: security update for shopware/core, shopware/platform (GHSA-35jp-8cgg-p4wj)

high Tenable Self-Hosted Container Security Plugin ID 409307

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is
injected into almost any Twig Template and allows to access to current language, currency information. The
context object allows also to switch for a short time the scope of the Context as a helper with a callable
function. The function can be called also from Twig and as the second parameter allows any callable, it's
possible to call from Twig any statically callable PHP function/method. It's not possible as customer to
provide any Twig code, the attacker would require access to Administration to exploit it using Mail
templates or using App Scripts. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older
versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin.
(CVE-2024-42356)

See Also

https://github.com/advisories/GHSA-35jp-8cgg-p4wj

Plugin Details

Severity: High

ID: 409307

Version: Revision 1.17

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.3

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2024-42356

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/8/2024

Vulnerability Publication Date: 8/8/2024

Reference Information

CVE: CVE-2024-42356