MEDIUM6.1
GHSA-5957-5crx-79jx
Zenario CMS vulnerable to CRLF injection
Quick fix
GHSA-5957-5crx-79jx — zendframework/zend-http: upgrade to the fixed version with the command below.
composer require zendframework/zend-http:^2.3.8Details
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zend-http
Introduced in:
2.0.0beta4Fixed in: 2.3.8Fix
composer require zendframework/zend-http:^2.3.8Packagist/zendframework/zend-http
Introduced in:
2.4.0rc1Fixed in: 2.4.1Fix
composer require zendframework/zend-http:^2.4.1Packagist/zendframework/zendframework
Introduced in:
2.0.0beta4Fixed in: 2.3.8Fix
composer require zendframework/zendframework:^2.3.8Packagist/zendframework/zendframework
Introduced in:
2.4.0rc1Fixed in: 2.4.1Fix
composer require zendframework/zendframework:^2.4.1Packagist/zendframework/zendframework1
Introduced in:
0Fixed in: 1.12.12Fix
composer require zendframework/zendframework1:^1.12.12Packagist/zendframework/zend-http
Introduced in:
0Fixed in: 1.12.12Fix
composer require zendframework/zend-http:^1.12.12References
- https://nvd.nist.gov/vuln/detail/CVE-2015-3154[ADVISORY]
- https://framework.zend.com/security/advisory/ZF2015-04[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-http/CVE-2015-3154.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2015-3154.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/CVE-2015-3154.yaml[WEB]
- https://github.com/zendframework/zendframework[PACKAGE]