PT-2014-4871 · Zend · Zend Framework+1

Published

2014-04-03

·

Updated

2017-11-04

·

CVE-2014-2685

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zend Framework 1 versions prior to 1.12.4 ZendOpenId versions prior to 2.0.2
Description The issue concerns the GenericConsumer class in the Consumer component and the Zend OpenId Consumer class, which do not fully adhere to the OpenID 2.0 protocol. Specifically, they only ensure that at least one field is signed, allowing remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Recommendations For Zend Framework 1 versions prior to 1.12.4, update to version 1.12.4 or later. For ZendOpenId versions prior to 2.0.2, update to version 2.0.2 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2685
DLA-251-1
DSA-3265-1
DSA-3265-2
MGASA-2014-0151

Affected Products

Zend Framework
Zendopenid