CVE-2023-2017
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypass of CVE-2023-22731.
EPSS 2.27% · 84.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| shopware | platform | 0 |
| shopware | core | 0 |
| Shopware AG | Shopware 6 | 6.5.0.0-rc1, 0 |
| shopware | shopware | 6.5.0.0, 6.1.0, 6.5.0.0 |
Timeline
- Apr 17, 2023 CVE Published
- Apr 18, 2023 EPSS Score
- Apr 28, 2023 CVE Updated
- May 25, 2023 EPSS Score
- Jul 2, 2023 EPSS Score
- Sep 15, 2023 EPSS Score
- Oct 22, 2023 EPSS Score
- Nov 29, 2023 EPSS Score
- Jan 5, 2024 EPSS Score
- Mar 20, 2024 EPSS Score
- Apr 26, 2024 EPSS Score
- Jun 3, 2024 EPSS Score
References
- https://starlabs.sg/advisories/23/23-2017/ exploit
- https://github.com/shopware/platform/security/advisories/GHSA-7v2v-9rm4-7m8f advisory
- https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-04-2023 vendor-advisory
- https://github.com/shopware/shopware/security/advisories/GHSA-7v2v-9rm4-7m8f url
- https://nvd.nist.gov/vuln/detail/CVE-2023-2017 advisory
- https://github.com/shopware/platform package
- https://github.com/shopware/platform/releases/tag/v6.4.20.1 url
- https://starlabs.sg/advisories/23/23-2017 url