Medium severity6.5NVD Advisory· Published Aug 16, 2021· Updated Jun 17, 2026
CVE-2021-37709
CVE-2021-37709
Description
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/platformPackagist | < 6.4.3.1 | 6.4.3.1 |
shopware/corePackagist | < 6.4.3.1 | 6.4.3.1 |
Affected products
4- shopware/platformv5Range: <= 6.4.3.0
- ghsa-coords2 versions
< 6.4.3.1+ 1 more
- (no CPE)range: < 6.4.3.1
- (no CPE)range: < 6.4.3.1
Patches
Vulnerability mechanics
References
4- github.com/shopware/platform/commit/a9f52abb6eb503654c492b6b2076f8d924831fecnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-54gp-qff8-946cghsaADVISORY
- github.com/shopware/platform/security/advisories/GHSA-54gp-qff8-946cnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37709ghsaADVISORY
News mentions
0No linked articles in our index yet.