Silencing Deprecation Messages Vulnerability
CVE-2024-42355
9.8CRITICAL
What is CVE-2024-42355?
A vulnerability exists in the Shopware Ecommerce Platform involving a new Twig Tag named sw_silent_feature_call
. This tag is intended to suppress deprecation messages but fails to properly escape a string parameter, which allows an attacker to execute arbitrary code. Users are strongly encouraged to upgrade to Shopware versions 6.6.5.1 or 6.5.8.13 to mitigate this risk. For users on older versions (6.2, 6.3, and 6.4), security measures are available via a dedicated plugin to address this critical concern.