shopware/core is vulnerable to Server-Side Request Forgery (SSRF)
63
Medium Risk
Shopware's media URL import uses FileUrlValidator to block fetches to internal IP addresses, but that check and the later download resolve the hostname separately. A DNS-rebinding hostname can therefore pass validation against a public address and then resolve to an internal address at fetch time. An authenticated Administration user with media permissions can import a crafted URL and retrieve responses from internal services or cloud-instance metadata.
You are affected if you are using a version that falls within the vulnerable range and Administration users or integrations with media permissions can import media from external URLs.
shopware/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.5.0.0 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant