VDB
Sign up
CRITICAL9.8

GHSA-mhpx-3rv8-wrjm

ZendFramework potential XML eXternal Entity injection vectors

Quick fix

GHSA-mhpx-3rv8-wrjm — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.12.4

Details

Numerous components utilizing PHP's `DOMDocument`, `SimpleXML`, and `xml_parse` functionality are vulnerable to two types of attacks:

- XML eXternal Entity (XXE) Injection attacks. The above mentioned extensions are insecure by default, allowing external entities to be specified by adding a specific DOCTYPE element to XML documents and strings. By exploiting this vulnerability an application may be coerced to open arbitrary files and/or TCP connections. - XML Entity Expansion (XEE) vectors, leading to Denial of Service vectors. XEE attacks occur when the XML DOCTYPE declaration includes XML entity definitions that contain either recursive or circular references; this leads to CPU and memory consumption, making Denial of Service exploits trivial to implement.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.12.0Fixed in: 1.12.4
Fixcomposer require zendframework/zendframework1:^1.12.4

References