VDB
Sign up
MEDIUM

GHSA-xp8p-9rq5-4wgv

ZendXml and Zend Framework contain XXE and XEE Vulnerabilities

Quick fix

GHSA-xp8p-9rq5-4wgv — zendframework/zendframework: upgrade to the fixed version with the command below.

composer require zendframework/zendframework:^2.4.6

Details

The `Zend_Xml_Security::scan` in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework
Introduced in: 2.0.0Fixed in: 2.4.6
Fixcomposer require zendframework/zendframework:^2.4.6
Packagist/zendframework/zendframework
Introduced in: 2.5.0Fixed in: 2.5.2
Fixcomposer require zendframework/zendframework:^2.5.2
Packagist/zendframework/zendframework1
Introduced in: 1.12.0Fixed in: 1.12.14
Fixcomposer require zendframework/zendframework1:^1.12.14
Packagist/zendframework/zendxml
Introduced in: 1.0.0Fixed in: 1.0.1
Fixcomposer require zendframework/zendxml:^1.0.1
Packagist/zendframework/zendframework
Introduced in: 1.12.0Fixed in: 1.12.14
Fixcomposer require zendframework/zendframework:^1.12.14

References