SCA: security update for shopware/core, shopware/platform (GHSA-93cw-f5jj-x85w)

high Tenable Self-Hosted Container Security Plugin ID 412988

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment
**without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`,
`filter`, `sort`. This allows a template to call any global PHP function and thus execute arbitrary code.
The attacker must have access to a Twig environment in order to exploit this vulnerability. This problem
has been fixed with 6.4.18.1 with an override of the specified filters until the integration of the
Sandbox extension has been finished. Users are advised to upgrade. Users of major versions 6.1, 6.2, and
6.3 may also receive this fix via a plugin. (CVE-2023-22731)

See Also

https://github.com/advisories/GHSA-93cw-f5jj-x85w

Plugin Details

Severity: High

ID: 412988

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-22731

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/17/2023

Vulnerability Publication Date: 1/17/2023

Reference Information

CVE: CVE-2023-22731

cwe: CWE-94