Description
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-251-1 | zendframework security update |
Debian DLA |
DLA-251-2 | zendframework regression update |
Debian DSA |
DSA-3265-1 | zendframework security update |
Debian DSA |
DSA-3265-2 | zendframework regression update |
EUVD |
EUVD-2022-2288 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657. |
Github GHSA |
GHSA-43xg-87xw-jpv8 | Several Zend Products Vulnerable to XXE and XEE attacks |
References
History
No history.
Subscriptions
Zend
Subscribe
Zend Framework
Subscribe
Zendopenid
Subscribe
Zendrest
Subscribe
Zendservice Amazon
Subscribe
Zendservice Api
Subscribe
Zendservice Audioscrobbler
Subscribe
Zendservice Nirvanix
Subscribe
Zendservice Slideshare
Subscribe
Zendservice Technorati
Subscribe
Zendservice Windowsazure
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:21:36.060Z
Reserved: 2014-03-30T00:00:00.000Z
Link: CVE-2014-2681
No data.
Status : Deferred
Published: 2014-11-16T00:59:00.123
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2681
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA