PT-2014-4871 · Zend · Zend Framework+1
Published
2014-04-03
·
Updated
2017-11-04
·
CVE-2014-2685
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zend Framework 1 versions prior to 1.12.4
ZendOpenId versions prior to 2.0.2
Description
The issue concerns the GenericConsumer class in the Consumer component and the Zend OpenId Consumer class, which do not fully adhere to the OpenID 2.0 protocol. Specifically, they only ensure that at least one field is signed, allowing remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Recommendations
For Zend Framework 1 versions prior to 1.12.4, update to version 1.12.4 or later.
For ZendOpenId versions prior to 2.0.2, update to version 2.0.2 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zend Framework
Zendopenid