{"id":"GHSA-f6p5-76fp-m248","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f6p5-76fp-m248","summary":"URL Rewrite vulnerability in multiple zendframework components","details":"zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.\n\nWhen these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.","published":"2022-04-28T21:09:54Z","modified":"2024-11-28T05:40:52.931974Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"zendframework/zend-diactoros","fixedVersion":"1.8.4"},{"ecosystem":"Packagist","name":"zendframework/zend-feed","fixedVersion":"2.10.3"},{"ecosystem":"Packagist","name":"zendframework/zend-http","fixedVersion":"2.8.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-diactoros/ZF2018-01.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-feed/ZF2018-01.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-http/ZF2018-01.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:40:52.931974Z"}}