QID 996692
Date Published: 2024-01-15
QID 996692: PHP (Composer) Security Update for zendframework/zendframework1 (GHSA-jh4x-4wmf-67pr)
(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers to cause a denial of service (CPU consumption) via recursive or circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-jh4x-4wmf-67pr for updates and patch information.
Vendor References
- GHSA-jh4x-4wmf-67pr -
github.com/advisories/GHSA-jh4x-4wmf-67pr
CVEs related to QID 996692
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jh4x-4wmf-67pr | zendframework/zendframework1 |
|