Zend Framework < 1.12.4 Multiple Vulnerabilities

Critical Nessus Network Monitor Plugin ID 9150


The remote host is using a version of Zend Framework that is vulnerable to multiple attack vectors.


Versions of Zend Framework earlier than 1.12.4 are vulnerable to the following security flaws :

- A flaw exists in the 'Consumer' component, as it is possible to login using an arbitrary OpenID account without knowing any secret information. With a specially crafted OpenID Provider, a remote attacker can impersonate any OpenID Identity to bypass the authentication mechanism. (CVE-2014-2684)
- A flaw in the 'Consumer' component, as elements in OpenID tokens are not properly checked to ensure they're signed. The framework considers a single signed element as sufficient whereas the specification states that more elements are required to be signed if present. This may allow a remote attacker to cause insufficiently signed OpenID tokens to be accepted as valid. (CVE-2014-2685)


Upgrade Zend Framework to version 1.12.4 or later.

See Also




Plugin Details

Severity: Critical

ID: 9150

Family: CGI

Published: 2016/03/15

Modified: 2016/03/15

Dependencies: 9135

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 9.8

Temporal Score: 9.1


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:thomas_breuss:zend_framework_integration_zend_framework

Patch Publication Date: 2014/03/06

Vulnerability Publication Date: 2014/03/06

Reference Information

CVE: CVE-2014-2684, CVE-2014-2685

BID: 66358