{"id":"GHSA-rf8f-hqjv-986p","summary":"Shopware Insecure Deserialization Vulnerability","details":"In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.","aliases":["CVE-2019-12799"],"modified":"2024-02-16T08:16:39.454275Z","published":"2022-05-24T16:48:00Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-07-31T20:21:38Z","nvd_published_at":"2019-06-13T20:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12799"},{"type":"WEB","url":"https://github.com/rapid7/metasploit-framework/pull/11828"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6m27-7cqj-2mxw"},{"type":"PACKAGE","url":"https://github.com/shopware5/shopware"},{"type":"WEB","url":"https://web.archive.org/web/20171112153855/https://blog.ripstech.com/2017/shopware-php-object-instantiation-to-blind-xxe"}],"affected":[{"package":{"name":"shopware/shopware","ecosystem":"Packagist","purl":"pkg:composer/shopware/shopware"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"last_affected":"5.6.0"}]}],"versions":["5.3.0","v5.3.4","v5.3.5","v5.3.6","v5.3.7","v5.4.0","v5.4.0-RC1","v5.4.1","v5.4.2","v5.4.3","v5.4.4","v5.4.5","v5.4.6","v5.5.0","v5.5.0-BETA1","v5.5.0-RC1","v5.5.1","v5.5.10","v5.5.2","v5.5.3","v5.5.4","v5.5.5","v5.5.6","v5.5.7","v5.5.8","v5.5.9","v5.6.0","v5.6.0-RC1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rf8f-hqjv-986p/GHSA-rf8f-hqjv-986p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}