Vulnerability record · CVE-2021-32717 · published 24 June 2021
CVE-2021-32717: Shopware information exposure vulnerability
Shopware · Shopware
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command `./bin/console s3:set-visibility` to correct your cloud file visibilities.
Description
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command `./bin/console s3:set-visibility` to correct your cloud file visibilities.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-06-2021 | PatchVendor Advisory |
| https://github.com/shopware/platform/commit/ba52f683372b8417a00e9014f481ed3d539f34b3 | PatchThird Party Advisory |
| https://github.com/shopware/platform/security/advisories/GHSA-vrf2-xghr-j52v | Third Party Advisory |
| https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-06-2021 | PatchVendor Advisory |
| https://github.com/shopware/platform/commit/ba52f683372b8417a00e9014f481ed3d539f34b3 | PatchThird Party Advisory |
| https://github.com/shopware/platform/security/advisories/GHSA-vrf2-xghr-j52v | Third Party Advisory |
Track CVE-2021-32717 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32717), CISA KEV, FIRST EPSS (scores of 2026-10-10). This page is refreshed as NVD updates the record.