VDB
Sign up
CRITICAL9.8

GHSA-m496-x567-f98c

Fixes a bug in Zend Framework's Stream HTTP Wrapper

Quick fix

GHSA-m496-x567-f98c — openmage/magento-lts: upgrade to the fixed version with the command below.

composer require openmage/magento-lts:^19.4.13

Details

### Impact CVE-2021-3007: Backport of Zend_Http_Response_Stream, added certain type checking as a way to prevent exploitation. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3007

This vulnerability is caused by the unsecured deserialization of an object. In versions higher than Zend Framework 3.0.0, the attacker abuses the Zend3 feature that loads classes from objects in order to upload and execute malicious code in the server. The code can be uploaded using the “callback” parameter, which in this case inserts a malicious code instead of the “callbackOptions” array.

### Patches _Has the problem been patched? What versions should users upgrade to?_ v20.0.9 v19.4.13

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/openmage/magento-lts
Introduced in: 0Fixed in: 19.4.13
Fixcomposer require openmage/magento-lts:^19.4.13
Packagist/openmage/magento-lts
Introduced in: 20.0.0Fixed in: 20.0.9
Fixcomposer require openmage/magento-lts:^20.0.9

References