PT-2014-4871 · Zend · Zend Framework+1
Publicado
2014-04-03
·
Atualizado
2017-11-04
·
CVE-2014-2685
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zend Framework 1 versions prior to 1.12.4
ZendOpenId versions prior to 2.0.2
Description
The issue concerns the GenericConsumer class in the Consumer component and the Zend OpenId Consumer class, which do not fully adhere to the OpenID 2.0 protocol. Specifically, they only ensure that at least one field is signed, allowing remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Recommendations
For Zend Framework 1 versions prior to 1.12.4, update to version 1.12.4 or later.
For ZendOpenId versions prior to 2.0.2, update to version 2.0.2 or later.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zend Framework
Zendopenid