GHSA-4j9x-g4x8-vcmf
ZendFramework potential XML eXternal Entity injection vectors
Quick fix
GHSA-4j9x-g4x8-vcmf — zendframework/zendframework1: upgrade to the fixed version with the command below.
composer require zendframework/zendframework1:^1.11.15Details
`Zend_Feed_Rss` and `Zend_Feed_Atom` were found to contain potential XML eXternal Entity (XXE) vectors due to insecure usage of PHP's DOM extension. External entities could be specified by adding a specific DOCTYPE element to feeds; exploiting this vulnerability could coerce opening arbitrary files and/or TCP connections.
A similar issue was fixed for 1.11.13 and 1.12.0, in the `Zend_Feed::import()` factory method; however, the reporter of the issue discovered that the individual classes contained similar functionality in their constructors which remained vulnerable.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.11.0Fixed in: 1.11.15composer require zendframework/zendframework1:^1.11.151.12.0Fixed in: 1.12.1composer require zendframework/zendframework1:^1.12.1