CVE-2024-22407
Broken Access Control order API in Shopware
4.9
MEDIUM
CVSS 3.1
EPSS 0.40%
描述
### Impact In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write' permissions for orders are still able to change the order state. ### Patches Update to Shopware 6.5.7.4 ### Workarounds For older versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
如何修補 CVE-2024-22407
要修補 CVE-2024-22407,請將受影響套件升級到下列已修補版本。
- —升級至 6.5.7.4 或更新版本
- —升級至 6.5.7.4 或更新版本
CVE-2024-22407 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 6.5.7.4
- from 0, < 6.5.7.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.9 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |