Lucene search

K
githubGitHub Advisory DatabaseGHSA-XP8P-9RQ5-4WGV
HistoryMay 17, 2022 - 3:16 a.m.

ZendXml and Zend Framework contain XXE and XEE Vulnerabilities

2022-05-1703:16:37
CWE-611
CWE-776
GitHub Advisory Database
github.com
27
zendxml
zend framework
security vulnerabilities
xxe
xee
php-fpm

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.079

Percentile

94.3%

The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

Affected configurations

Vulners
Node
zendframeworkzendframeworkRange1.12.01.12.14
OR
zendframeworkzendxmlRange1.0.01.0.1
OR
zendframeworkzendframework1Range1.12.01.12.14
OR
zendframeworkzendframeworkRange2.5.02.5.2
OR
zendframeworkzendframeworkRange2.0.02.4.6
VendorProductVersionCPE
zendframeworkzendframework*cpe:2.3:a:zendframework:zendframework:*:*:*:*:*:*:*:*
zendframeworkzendxml*cpe:2.3:a:zendframework:zendxml:*:*:*:*:*:*:*:*
zendframeworkzendframework1*cpe:2.3:a:zendframework:zendframework1:*:*:*:*:*:*:*:*

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.079

Percentile

94.3%