Shopware
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*
- >= 4.0.0, < 4.0.7
- >= 3.0.0, < 3.0.12
- < 2.0.16
A vulnerability in the Shopware security plugin allows for information disclosure by exposing active security fixes through the `/api/_info/config` route. This could lead to an unwanted exposure of the system's state. The vulnerability affects Shopware versions 4.0.0 prior to 4.0.7, 3.0.0 prior to 3.0.12, and versions prior to 2.0.16.
The vulnerability could result in unauthorized information disclosure, revealing details about active security fixes and potentially the system's state.
Users can upgrade to Shopware versions 4.0.7, 3.0.12, or 2.0.16 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.