Lucene search

K
jvnJapan Vulnerability NotesJVN:24713981
HistoryAug 21, 2013 - 12:00 a.m.

JVN#24713981: PHP OpenID Library vulnerable to XML external entity injection

2013-08-2100:00:00
Japan Vulnerability Notes
jvn.jp
27

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.006 Low

EPSS

Percentile

79.3%

The PHP OpenID Library contains an XML external entity injection vulnerability.

Impact

When processing specially crafted XRDS data, information on the server may be disclosed or server resources may be consumed excessively.

Solution

Apply a Patch
The source code in the repository has been fixed. Please apply the fixed code according to the code committed by the developer.

Products Affected

  • PHP OpenID Library versions 2.2.2 and earlier

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.006 Low

EPSS

Percentile

79.3%