CVE-2023-34098

MEDIUM

Shopware 5.6.0-5.7.17 - Exposure of Sensitive Information via .htaccess Misconfiguration

Title source: llm
STIX 2.1

Description

Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the specific Shopware version in a deployment might be determined by an attacker, which could be used for further attacks. Users are advised to update to version 5.7.18. There are no known workarounds for this vulnerability.

Scores

CVSS v3 5.3
EPSS 0.0050
EPSS Percentile 38.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
shopware/shopware 5.6.0 - 5.7.18
shopware/shopware 5.6.0 - 5.7.18Packagist
Published Jun 27, 2023
Tracked Since Feb 18, 2026