Server-Side Request Forgery (SSRF) in Shopware Flow Builder
CVE-2024-22408
7.6HIGH
What is CVE-2024-22408?
The Flow Builder functionality in Shopware's open headless commerce platform contains a vulnerability that inadequately validates the URLs used in the 'call webhook' action. This lack of proper validation allows attackers to send web requests to internal hosts, potentially compromising the security of the affected systems. To mitigate this vulnerability, users are advised to update to the latest Commercial Plugin release, version 6.5.7.4, or install the Security Plugin for existing installations of Shopware 6.4 and earlier versions. Regular updates and adherence to security recommendations are essential for ensuring the integrity of Shopware applications.
Affected Version(s)
shopware < 6.5.7.4