VDB
Sign up
HIGH7.5

GHSA-4j9x-g4x8-vcmf

ZendFramework potential XML eXternal Entity injection vectors

Quick fix

GHSA-4j9x-g4x8-vcmf — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.11.15

Details

`Zend_Feed_Rss` and `Zend_Feed_Atom` were found to contain potential XML eXternal Entity (XXE) vectors due to insecure usage of PHP's DOM extension. External entities could be specified by adding a specific DOCTYPE element to feeds; exploiting this vulnerability could coerce opening arbitrary files and/or TCP connections.

A similar issue was fixed for 1.11.13 and 1.12.0, in the `Zend_Feed::import()` factory method; however, the reporter of the issue discovered that the individual classes contained similar functionality in their constructors which remained vulnerable.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.11.0Fixed in: 1.11.15
Fixcomposer require zendframework/zendframework1:^1.11.15
Packagist/zendframework/zendframework1
Introduced in: 1.12.0Fixed in: 1.12.1
Fixcomposer require zendframework/zendframework1:^1.12.1

References