Release notes Shopware 6.6.10.23
Abstract
Shopware 6.6.10.23 is a patch release focused on security, addressing a total of nine vulnerabilities including App Script sandbox escape, host-header password-reset poisoning, SQL injection risks, DNS rebinding issues, and missing rate limiting, among others.
Users are strongly encouraged to update to ensure their systems remain secure. If you cannot update immediately to the latest version, consider using the Shopware Security Plugin instead.
System requirements
- tested on PHP 8.2 and 8.4
- tested on MySQL 8 and MariaDB 11
Improvements
(No notable improvements in this patch release)
Fixed bugs
- GHSA-6qhw-38wm-7g7h - App Script sandbox escape
- GHSA-xj2c-8fw5-mr6m - Host-header password-reset poisoning
- GHSA-xrcf-c96g-q5hr - Custom-entity SQL/DDL injection
- GHSA-p37c-pm9p-7vm5 - Store API aggregation-name SQL injection
- GHSA-4wpv-5fvv-c3xp - ACL-role mass assignment
- GHSA-674c-5376-96rv - Disclosure of unapproved product reviews
- GHSA-fgjq-45xv-rj8r - Media-import DNS rebinding
- GHSA-rrc3-p9vx-5373 - App System/webhook DNS rebinding
- GHSA-f497-xgx3-22hq - Missing guest-document rate limiting
Credits
Thanks to all diligent friends for helping us make Shopware better and better with each pull request!
More resources
- Detailed diff on Github to the former version
- Installation overview
- Update from a previous installation
Get in touch
Discuss about decisions, bugs you might stumble upon, etc in our community discord. See you there 😉