QID 996685
Date Published: 2024-01-15
QID 996685: PHP (Composer) Security Update for zendframework/zendframework1 (GHSA-9m5v-vq4f-mrvf)
The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9m5v-vq4f-mrvf for updates and patch information.
Vendor References
- GHSA-9m5v-vq4f-mrvf -
github.com/advisories/GHSA-9m5v-vq4f-mrvf
CVEs related to QID 996685
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9m5v-vq4f-mrvf | zendframework/zendframework1 |
|