Unauthenticated credential disclosure via JSON response
Published Feb 26, 2021 · Updated Aug 4, 2024
Information disclosure in Amazon Pay Plugin before 9.4.2 for Shopware allows remote attackers to read the merchant Amazon Secret Access Key via JSON. The plugin adds the secret to a JSON response when the Enlight_Controller is used because a required authorization check is missing. Exploitation requires the JSON renderer and another plugin combination that reaches this controller; exposure compromises the credential's confidentiality and can enable unauthorized Amazon Pay activity.
Summary
What happened
Information disclosure in Amazon Pay Plugin before 9.4.2 for Shopware allows remote attackers to read the merchant Amazon Secret Access Key via JSON. The plugin adds the secret to a JSON response when the Enlight_Controller is used because a required authorization check is missing. Exploitation requires the JSON renderer and another plugin combination that reaches this controller; exposure compromises the credential's confidentiality and can enable unauthorized Amazon Pay activity.
The record
- CVE
- CVE-2020-28199
- Published
- Feb 26, 2021
- Updated
- Aug 4, 2024
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-200
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Feb 26, 2021CVE publishedPublication date reported by the CVE source.
- Aug 4, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- aramido-2020-006 disclosure of Amazon secret access keyproof of concept · unverified
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo