In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| shopware/core(Packagist) | 6.0.0 | 6.2.3 | N/A |
| shopware/platform(Packagist) | 6.0.0 | 6.2.3 | N/A |
CVSS Metrics