Vulnerability record · CVE-2023-2017 · published 17 April 2023
CVE-2023-2017: Shopware code injection vulnerability
Shopware · Shopware
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypass of CVE-2023-22731.
Description
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypass of CVE-2023-22731.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-04-2023 | Vendor Advisory |
| https://github.com/shopware/platform/security/advisories/GHSA-7v2v-9rm4-7m8f | Vendor Advisory |
| https://starlabs.sg/advisories/23/23-2017/ | ExploitMitigationThird Party Advisory |
| https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-04-2023 | Vendor Advisory |
| https://github.com/shopware/platform/security/advisories/GHSA-7v2v-9rm4-7m8f | Vendor Advisory |
| https://starlabs.sg/advisories/23/23-2017/ | ExploitMitigationThird Party Advisory |
Track CVE-2023-2017 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2017), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.