Description
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-251-1 | zendframework security update |
Debian DLA |
DLA-251-2 | zendframework regression update |
Debian DSA |
DSA-3265-1 | zendframework security update |
Debian DSA |
DSA-3265-2 | zendframework regression update |
EUVD |
EUVD-2022-2669 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532. |
Github GHSA |
GHSA-5wm2-38q5-5rxv | Several Zend Products Vulnerable to XXE and XEE attacks |
References
History
No history.
Subscriptions
Zend
Subscribe
Zend Framework
Subscribe
Zendopenid
Subscribe
Zendrest
Subscribe
Zendservice Amazon
Subscribe
Zendservice Api
Subscribe
Zendservice Audioscrobbler
Subscribe
Zendservice Nirvanix
Subscribe
Zendservice Slideshare
Subscribe
Zendservice Technorati
Subscribe
Zendservice Windowsazure
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:21:36.135Z
Reserved: 2014-03-30T00:00:00.000Z
Link: CVE-2014-2683
No data.
Status : Modified
Published: 2014-11-16T00:59:03.920
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-2683
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA