Lucene search

K
osvGoogleOSV:GHSA-9M5V-VQ4F-MRVF
HistoryMay 17, 2022 - 5:10 a.m.

Zend Framework XXE Vulnerability

2022-05-1705:10:46
Google
osv.dev
13
zend framework
xxe vulnerability
remote attackers
arbitrary files
http requests
denial of service
xml external entity
security issue

AI Score

6.6

Confidence

High

EPSS

0.003

Percentile

70.3%

The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack.

AI Score

6.6

Confidence

High

EPSS

0.003

Percentile

70.3%