Release notes Shopware 6.7.14.1
Abstract
Shopware 6.7.14.1 is a security release. Please update as soon as possible! If you cannot update for some reason it is strongly recommended to make use of the Security plugin.
System requirements
- tested on PHP 8.2, 8.4 and 8.5
- tested on MySQL 8, MySQL 9.7, MariaDB 11 and MariaDB 12
Improvements
(No notable improvements in this patch release)
Fixed bugs
- GHSA-r432-q883-wgvf - Webhook ACL / sensitive webhook data exposure
- GHSA-2qxr-vvj4-5934 - Range-aggregation SQL injection
- GHSA-p589-2ff8-3wfw - User admin privilege escalation
- GHSA-8xfc-pww7-3rm5 - Integration admin privilege escalation via Sync API
- GHSA-mch6-932v-3cm8 - Newsletter double-opt-in bypass
Credits
Thanks to all diligent friends for helping us make Shopware better and better with each pull request!
More resources
- Detailed diff on Github to the former version
- Installation overview
- Update from a previous installation
Get in touch
Discuss about decisions, bugs you might stumble upon, etc in our community discord. See you there 😉