Improper Control of Generation of Code in Twig Rendered Views in Shopware
CVE-2023-2017
What is CVE-2023-2017?
A Server-side Template Injection vulnerability exists in Shopware 6 versions up to v6.4.20.0 and between v6.5.0.0-rc1 to v6.5.0.0-rc4. This flaw enables remote attackers to exploit a Twig environment without the necessary Sandbox extension, leading to a bypass of validation checks. Attackers can invoke arbitrary PHP functions and execute dangerous code by providing fully-qualified names via an array of strings in callable references. Users should update to v6.4.20.1 to mitigate this risk and enhance security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Shopware 6 0 <= 6.4.20.0
Shopware 6 6.5.0.0-rc1 <= 6.5.0.0-rc4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
