{"id":"GHSA-fq4p-86hh-42v9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-fq4p-86hh-42v9","summary":"Zend-Diactoros URL Rewrite vulnerability","details":"zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.\n\nWhen these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.","published":"2024-06-07T22:07:30Z","modified":"2024-12-04T05:32:07.473740Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"zendframework/zend-diactoros","fixedVersion":"1.8.4"}],"fix":{"url":"https://github.com/zendframework/zend-diactoros/commit/3a4f44f7f89f7007f3c3e4ca69ac23874f8a4093","label":"zendframework/zend-diactoros@3a4f44f"},"references":[{"type":"WEB","url":"https://github.com/zendframework/zend-diactoros/commit/3a4f44f7f89f7007f3c3e4ca69ac23874f8a4093"},{"type":"WEB","url":"https://github.com/zendframework/zend-diactoros/commit/736ffa7c2bfa4a60e8a10acb316fa2ac456c5fba"},{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2018-01"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-diactoros/ZF2018-01.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zend-diactoros"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:32:07.473740Z"}}