In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://www.shopware.com/en/changelog/#6-2-3 | release notes vendor advisory |
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020 | vendor advisory |