MEDIUM
GHSA-w5mj-j45q-m638
ZendFramework1 Potential Security Issues in Bundled Dojo Library
Quick fix
GHSA-w5mj-j45q-m638 — zendframework/zendframework1: upgrade to the fixed version with the command below.
composer require zendframework/zendframework1:^1.9.8Details
In mid-March, 2010, the Dojo Foundation issued a Security Advisory indicating potential security issues with specific files in Dojo Toolkit. Details of the advisory may be found on the Dojo website:
http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory/ In particular, several files in the Dojo tree were identified as having potential exploits, and the Dojo team also advised disabling or removing any PHP scripts in the tree when deploying to production.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zendframework1
Introduced in:
1.9.0Fixed in: 1.9.8Fix
composer require zendframework/zendframework1:^1.9.8Packagist/zendframework/zendframework1
Introduced in:
1.10.0Fixed in: 1.10.3Fix
composer require zendframework/zendframework1:^1.10.3References
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/ZF2010-07.yaml[WEB]
- https://github.com/zendframework/zf1[PACKAGE]
- https://web.archive.org/web/20210509072723/https://framework.zend.com/security/advisory/ZF2010-07[WEB]
- http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory[WEB]