CRITICAL9.8
GHSA-v59p-p692-v382
Zend Framework Allows SQL Injection
Quick fix
GHSA-v59p-p692-v382 — zendframework/zendframework: upgrade to the fixed version with the command below.
composer require zendframework/zendframework:^2.2.10Details
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zendframework
Introduced in:
0Fixed in: 2.2.10Fix
composer require zendframework/zendframework:^2.2.10Packagist/zendframework/zendframework
Introduced in:
2.3.0Fixed in: 2.3.5Fix
composer require zendframework/zendframework:^2.3.5Packagist/zendframework/zend-db
Introduced in:
0Fixed in: 2.2.10Fix
composer require zendframework/zend-db:^2.2.10Packagist/zendframework/zend-db
Introduced in:
2.3.0Fixed in: 2.3.5Fix
composer require zendframework/zend-db:^2.3.5References
- https://nvd.nist.gov/vuln/detail/CVE-2015-0270[ADVISORY]
- https://github.com/zendframework/zendframework/commit/569f18228f5fc84534af6ff2f367ca1a7143ec65[WEB]
- https://framework.zend.com/security/advisory/ZF2015-02[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-db/CVE-2015-0270.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2015-0270.yaml[WEB]
- https://github.com/zendframework/zendframework[PACKAGE]