QID 996671
Date Published: 2024-01-15
QID 996671: PHP (Composer) Security Update for zendframework/zendframework1 (GHSA-h5p3-7mg6-hgj4)
(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-h5p3-7mg6-hgj4 for updates and patch information.
Vendor References
- GHSA-h5p3-7mg6-hgj4 -
github.com/advisories/GHSA-h5p3-7mg6-hgj4
CVEs related to QID 996671
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h5p3-7mg6-hgj4 | zendframework/zendframework1 |
|