Zend Framework < 1.12.4 Multiple Vulnerabilities

Critical Nessus Network Monitor Plugin ID 9150

Synopsis

The remote host is using a version of Zend Framework that is vulnerable to multiple attack vectors.

Description

Versions of Zend Framework earlier than 1.12.4 are vulnerable to the following security flaws :

- A flaw exists in the 'Consumer' component, as it is possible to login using an arbitrary OpenID account without knowing any secret information. With a specially crafted OpenID Provider, a remote attacker can impersonate any OpenID Identity to bypass the authentication mechanism. (CVE-2014-2684)
- A flaw in the 'Consumer' component, as elements in OpenID tokens are not properly checked to ensure they're signed. The framework considers a single signed element as sufficient whereas the specification states that more elements are required to be signed if present. This may allow a remote attacker to cause insufficiently signed OpenID tokens to be accepted as valid. (CVE-2014-2685)

Solution

Upgrade Zend Framework to version 1.12.4 or later.

See Also

http://framework.zend.com

http://framework.zend.com/security/advisory/ZF2014-02

http://framework.zend.com/changelog/1.12.4

Plugin Details

Severity: Critical

ID: 9150

Family: CGI

Published: 2016/03/15

Modified: 2016/03/15

Dependencies: 9135

Risk Information

Risk Factor: Critical

CVSSv2

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSSv3

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:thomas_breuss:zend_framework_integration_zend_framework

Patch Publication Date: 2014/03/06

Vulnerability Publication Date: 2014/03/06

Reference Information

CVE: CVE-2014-2684, CVE-2014-2685

BID: 66358