GHSA-xx8f-qf9f-5fgw

    Dashboard / Vulnerabilities / GHSA-xx8f-qf9f-5fgw

    GHSA-xx8f-qf9f-5fgw

    Published: 8 Jun 2021Last Modified: 22 Apr 2024
    Aliases:

    Summary: Remote code execution in zendframework and laminas-http

    Details: Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized.

    Affected packages

    Package

    Name: zendframework/zendframework

    Purl: pkg:composer/zendframework/zendframework

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    2.0.0
    2.0.0beta4
    2.0.0beta5
    2.0.0rc1
    2.0.0rc2
    2.0.0rc3
    2.0.0rc4
    2.0.0rc5
    2.0.0rc6
    2.0.0rc7
    2.0.1
    2.0.2
    2.0.3
    2.0.4
    2.0.5
    2.0.6
    2.0.7
    2.0.8

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-xx8f-qf9f-5fgw | CVE-DB