Release notes Shopware 6.7.13.1
Abstract
Shopware 6.7.13.1 is a patch release that addresses a total of eleven issues, consisting of nine security vulnerabilities and two general bug fixes. The security fixes cover critical areas such as App Script sandbox escape, SQL injection risks, DNS rebinding, path traversal, and missing rate limiting, alongside fixes for Elasticsearch reindexing and Twig environment type hinting.
Users are advised to update promptly to protect their systems.
System requirements
- tested on PHP 8.2, 8.4 and 8.5
- tested on MySQL 8 and MariaDB 11
Improvements
(No notable improvements in this patch release)
Fixed bugs
- GHSA-6qhw-38wm-7g7h - App Script sandbox escape
- GHSA-xj2c-8fw5-mr6m - Host-header password-reset poisoning
- GHSA-xrcf-c96g-q5hr - Custom-entity SQL/DDL injection
- GHSA-p37c-pm9p-7vm5 - Store API aggregation-name SQL injection
- GHSA-4wpv-5fvv-c3xp - ACL-role mass assignment
- GHSA-674c-5376-96rv - Disclosure of unapproved product reviews
- GHSA-p67w-3mq7-rw2g - Writable media extension path traversal
- GHSA-fgjq-45xv-rj8r - Media-import DNS rebinding
- GHSA-rrc3-p9vx-5373 - App System/webhook DNS rebinding
- GHSA-f497-xgx3-22hq - Missing guest-document rate limiting
- fix(elasticsearch): reindex instead of aborting when an analyzer is missing from the live index by @vienthuong (#18702)
- fix: type hint base twig environment in document renderers by @larskemper
Credits
Thanks to all diligent friends for helping us make Shopware better and better with each pull request!
More resources
- Detailed diff on Github to the former version
- Installation overview
- Update from a previous installation
Get in touch
Discuss about decisions, bugs you might stumble upon, etc in our community discord. See you there 😉