PT-2024-40028 · Zend · Zend Dom+3

Published

2024-06-07

·

Updated

2024-06-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zend Dom, Zend Feed, Zend Soap, and Zend XmlRpc (affected versions not specified)
Description The issue concerns XML Entity Expansion (XEE) vectors, which can lead to Denial of Service attacks. XEE attacks happen when the XML DOCTYPE declaration includes XML entity definitions with recursive or circular references, causing CPU and memory consumption. This makes it easy to implement Denial of Service exploits.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XML Entity Expansion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-2JX7-XG83-J2M7

Affected Products

Zend Dom
Zend-Feed
Zend Soap
Zend Xmlrpc