PT-2024-40058 · Zend · Zendopenid
Published
2024-06-07
·
Updated
2024-06-07
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ZendOpenId (or Zend OpenId in ZF1) (affected versions not specified)
Description
The issue allows an attacker to login using an arbitrary OpenID account without knowing any secret information by utilizing a malicious OpenID Provider. This means it is possible to impersonate any OpenID Identity, such as those from MyOpenID or Google, against the framework. Furthermore, the Consumer component accepts OpenID tokens with arbitrary signed elements, failing to check if all required parameters (e.g.,
openid.claimed id and openid.endpoint url) are signed, which contradicts the OpenID specification that mandates the signing of at least op endpoint, return to, response nonce, assoc handle, and, if present, claimed id and identity.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zendopenid