
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity vulnerability was discovered in Zend_XmlRpc, identified as GHSA-229x-22xc-2f2w. The vulnerability affects Zendframework versions greater than or equal to 1.0.0 and less than 1.11.13. The issue was disclosed on June 22, 2012, and involves XML eXternal Entity (XXE) Injection attacks in the Zend_XmlRpc component (Zend Advisory, GitHub Advisory).
The vulnerability stems from the insecure usage of the SimpleXMLElement class (SimpleXML PHP extension) when parsing XML data. External entities can be specified by adding a specific DOCTYPE element to XML-RPC requests. The vulnerability has been assigned a CVSS v3.1 score of 8.6 (High), with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. The vulnerability is classified under CWE-611 (GitHub Advisory).
When exploited, this vulnerability allows attackers to coerce the application to open arbitrary files and/or TCP connections, potentially leading to unauthorized access to sensitive files on the system (Zend Advisory).
The vulnerability can be exploited remotely with low attack complexity and requires no privileges or user interaction. The attack vector is network-based, and the scope is changed, indicating that the vulnerable component impacts resources beyond its security scope (GitHub Advisory).
The vulnerability was patched by implementing libxml_disable_entity_loader() in the Request and Response implementations of Zend_XmlRpc, which disables XXE parsing. Additional attack vectors were identified and patched in Zend_Dom, Zend_Feed, and Zend_Soap components. Users are recommended to upgrade to version 1.11.13 or greater immediately (Zend Advisory).
The vulnerability was identified and reported by Johannes Greil and Kestutis Gudinavicius from SEC Consult Vulnerability Lab, with additional vectors discovered by Pádraic Brady (Zend Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."