Security Advisory: Amazon Secret Key Publicly Accessible (CVE-2020-28199)

Security researchers from aramido discovered a security vulnerability in an Amazon Pay plugin for Shopware 5, which is developed by best it AG. The plugin is used by numerous customers as an Amazon Pay integration for Shopware and is widely distributed. In accordance with aramido's guidelines for the responsible disclosure of security vulnerabilities , aramido reported the vulnerability to the manufacturer for remediation, which was completed by September 25, 2020. The security advisory formulated by aramido can be viewed publicly. In coordination with the manufacturer and Amazon Pay, the publication of the vulnerability was scheduled for Q1 2021. After the coordinated disclosure, Amazon and the manufacturer reacted immediately, professionally developed a solution with the parties involved, and quickly provided an updated plugin version.

Unauthorized third parties could have read the Amazon Secret Access Key

The plugin extends Shopware with functionality for payment with Amazon Pay. Security researchers were able to determine that unauthenticated users could potentially read the Secret Access Key, which the merchant uses for authentication with Amazon Pay, due to insufficient validation. The vulnerability can be exploited if the JSON renderer is enabled in conjunction with other plugins. If the Enlight_Controller is used, the secret is added to a JSON response due to a missing check.

Operators of Shopware 5 shops with Amazon Pay should check the use and currency of the plugin

The manufacturer requests an update of the plugin to at least version 9.4.2 as soon as possible to close the vulnerability. Since the vulnerability is very easy to exploit, the risk of compromising the key is very high. In addition, after an update, the key should be rotated (created anew) to counter any possible previous theft of the key. Furthermore, activities at Amazon Pay should be checked for anomalies.

The security vulnerability was reported by aramido to the manufacturer on September 14, 2020. The vulnerability was assigned CVE-2020-28199. best it AG reported the remediation on September 25, 2020, and published a new version of the plugin on September 29, 2020. After coordination with best it AG and Amazon Pay, a coordinated process for notifying customers about the vulnerability was initiated, and publication was set for February 1, 2021.