Release notes Shopware 6.6.10.23
Abstract
Shopware 6.6.10.23 is a patch release focused on security, addressing a total of nine vulnerabilities including App Script sandbox escape, host-header password-reset poisoning, SQL injection risks, DNS rebinding issues, and missing rate limiting, among others.
Users are strongly encouraged to update to ensure their systems remain secure.
System requirements
- tested on PHP 8.2 and 8.4
- tested on MySQL 8 and MariaDB 11
Improvements
(No notable improvements in this patch release)
Fixed bugs
- GHSA-6qhw-38wm-7g7h - App Script sandbox escape
- GHSA-xj2c-8fw5-mr6m - Host-header password-reset poisoning
- GHSA-xrcf-c96g-q5hr - Custom-entity SQL/DDL injection
- GHSA-p37c-pm9p-7vm5 - Store API aggregation-name SQL injection
- GHSA-4wpv-5fvv-c3xp - ACL-role mass assignment
- GHSA-674c-5376-96rv - Disclosure of unapproved product reviews
- GHSA-fgjq-45xv-rj8r - Media-import DNS rebinding
- GHSA-rrc3-p9vx-5373 - App System/webhook DNS rebinding
- GHSA-f497-xgx3-22hq - Missing guest-document rate limiting
Credits
Thanks to all diligent friends for helping us make Shopware better and better with each pull request!
More resources
- Detailed diff on Github to the former version
- Installation overview
- Update from a previous installation
Get in touch
Discuss about decisions, bugs you might stumble upon, etc in our community discord. See you there 😉