VDB
Sign up
MEDIUM6.1

GHSA-5957-5crx-79jx

Zenario CMS vulnerable to CRLF injection

Quick fix

GHSA-5957-5crx-79jx — zendframework/zend-http: upgrade to the fixed version with the command below.

composer require zendframework/zend-http:^2.3.8

Details

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zend-http
Introduced in: 2.0.0beta4Fixed in: 2.3.8
Fixcomposer require zendframework/zend-http:^2.3.8
Packagist/zendframework/zend-http
Introduced in: 2.4.0rc1Fixed in: 2.4.1
Fixcomposer require zendframework/zend-http:^2.4.1
Packagist/zendframework/zendframework
Introduced in: 2.0.0beta4Fixed in: 2.3.8
Fixcomposer require zendframework/zendframework:^2.3.8
Packagist/zendframework/zendframework
Introduced in: 2.4.0rc1Fixed in: 2.4.1
Fixcomposer require zendframework/zendframework:^2.4.1
Packagist/zendframework/zendframework1
Introduced in: 0Fixed in: 1.12.12
Fixcomposer require zendframework/zendframework1:^1.12.12
Packagist/zendframework/zend-http
Introduced in: 0Fixed in: 1.12.12
Fixcomposer require zendframework/zend-http:^1.12.12

References