The following issue has been identified:
A possibility for data leak was found.
Resolved in OXID eShop version 4.4.6.
When admin panel uses SSL, in some rare cases non-SSL linkes approach for data transfer. This may lead to a possible “man in the middle attack”.
No exploits are known as of today.
Affected products, releases and platforms
- OXID eShop Enterprise Edition
- OXID eShop Professional Edition
- OXID eShop Community Edition
- Professional, Enterprise and Community Edition: 188.8.131.52_13895, 184.108.40.206_13934, 220.127.116.11_14260, 18.104.22.168_14455, 22.214.171.124_14842, 126.96.36.199_14967, 188.8.131.52_15990, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 4.2.0, 4.3.0, 4.3.1, 4.3.2, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.4.4 and 4.4.5.
- Above releases are affected on all platforms.
The issue has been addressed in the following releases:
- OXID eShop Professional Edition version 4.4.6
- OXID eShop Enterprise Edition version 4.4.6
- OXID eShop Community Edition version 4.4.6
The security issue has been found during one of our regular security audits.
How to report security issues
Learn how to report security issues in the Security overview page.