Description
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly share the libxml_disable_entity_loader setting between threads, which might allow remote attackers to conduct XML External Entity (XXE) attacks via an XML external entity declaration in conjunction with an entity reference. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-251-1 | zendframework security update |
Debian DLA |
DLA-251-2 | zendframework regression update |
Debian DSA |
DSA-3265-1 | zendframework security update |
Debian DSA |
DSA-3265-2 | zendframework regression update |
EUVD |
EUVD-2022-3982 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly share the libxml_disable_entity_loader setting between threads, which might allow remote attackers to conduct XML External Entity (XXE) attacks via an XML external entity declaration in conjunction with an entity reference. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657. |
Github GHSA |
GHSA-gp39-h9c2-qw79 | Several Zend Products Vulnerable to XXE and XEE attacks |
References
History
No history.
Subscriptions
Zend
Subscribe
Zend Framework
Subscribe
Zendopenid
Subscribe
Zendrest
Subscribe
Zendservice Amazon
Subscribe
Zendservice Api
Subscribe
Zendservice Audioscrobbler
Subscribe
Zendservice Nirvanix
Subscribe
Zendservice Slideshare
Subscribe
Zendservice Technorati
Subscribe
Zendservice Windowsazure
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:21:36.052Z
Reserved: 2014-03-30T00:00:00.000Z
Link: CVE-2014-2682
No data.
Status : Deferred
Published: 2014-11-16T00:59:02.827
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2682
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA