shopware/core is vulnerable to Information Disclosure
53
Medium Risk
Shopware's Store API applied product-review visibility rules only to the top-level productReviews association. Criteria that loaded reviews through a nested association skipped those checks, so an unauthenticated visitor could read the content, rating, and display name of reviews still awaiting moderation. The patch applies the same visibility rules to nested productReviews associations: approved reviews, plus the pending reviews of the logged-in customer.
You are affected if you are using a version that falls within the vulnerable range and your shop collects product reviews that require approval before publication. An unauthenticated Store API client can load those unpublished reviews through a nested productReviews association.
shopware/core is vulnerable to Information Disclosure in versions 6.5.8.15 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant