PT-2014-4871 · Zend · Zend Framework+1

Publicado

2014-04-03

·

Atualizado

2017-11-04

·

CVE-2014-2685

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zend Framework 1 versions prior to 1.12.4 ZendOpenId versions prior to 2.0.2
Description The issue concerns the GenericConsumer class in the Consumer component and the Zend OpenId Consumer class, which do not fully adhere to the OpenID 2.0 protocol. Specifically, they only ensure that at least one field is signed, allowing remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Recommendations For Zend Framework 1 versions prior to 1.12.4, update to version 1.12.4 or later. For ZendOpenId versions prior to 2.0.2, update to version 2.0.2 or later.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2685
DLA-251-1
DSA-3265-1
DSA-3265-2
MGASA-2014-0151

Produtos afetados

Zend Framework
Zendopenid