{"id":"GHSA-cg8w-5jrc-675g","aliases":[],"url":"https://o3.security/vulnerability/GHSA-cg8w-5jrc-675g","summary":"Zend-HTTP URL Rewrite vulnerability","details":"zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.\n\nWhen these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.","published":"2024-06-07T21:52:12Z","modified":"2024-12-04T05:50:28.310284Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"zendframework/zend-http","fixedVersion":"2.8.1"}],"fix":{"url":"https://github.com/zendframework/zend-http/commit/44197164a270259116162a442f639085ea24094a","label":"zendframework/zend-http@4419716"},"references":[{"type":"WEB","url":"https://github.com/zendframework/zend-http/commit/44197164a270259116162a442f639085ea24094a"},{"type":"WEB","url":"https://github.com/zendframework/zend-http/commit/5234f4a9e8137b731ab95d6a17879d4eb8fb9e39"},{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2018-01"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-http/ZF2018-01.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zend-http"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:50:28.310284Z"}}