Server-Side Request Forgery (SSRF) in Shopware Flow Builder
CVE-2024-22408

7.6HIGH

Key Information:

Vendor

Shopware

Status
Vendor
CVE Published:
16 January 2024

What is CVE-2024-22408?

The Flow Builder functionality in Shopware's open headless commerce platform contains a vulnerability that inadequately validates the URLs used in the 'call webhook' action. This lack of proper validation allows attackers to send web requests to internal hosts, potentially compromising the security of the affected systems. To mitigate this vulnerability, users are advised to update to the latest Commercial Plugin release, version 6.5.7.4, or install the Security Plugin for existing installations of Shopware 6.4 and earlier versions. Regular updates and adherence to security recommendations are essential for ensuring the integrity of Shopware applications.

Affected Version(s)

shopware < 6.5.7.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.