{"id":"GHSA-jmmp-vh96-78rm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jmmp-vh96-78rm","summary":"Zend-Feed URL Rewrite vulnerability","details":"zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.\n\nWhen these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.","published":"2024-06-07T22:01:20Z","modified":"2024-12-04T05:31:32.946307Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"zendframework/zend-feed","fixedVersion":"2.10.3"}],"fix":{"url":"https://github.com/zendframework/zend-feed/commit/6641f4cf3f4586c63f83fd70b6d19966025c8888","label":"zendframework/zend-feed@6641f4c"},"references":[{"type":"WEB","url":"https://github.com/zendframework/zend-feed/commit/6641f4cf3f4586c63f83fd70b6d19966025c8888"},{"type":"WEB","url":"https://github.com/zendframework/zend-feed/commit/b28589c49bae3ee215cff904cc0be368e6409cd8"},{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2018-01"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-feed/ZF2018-01.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zend-feed"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:31:32.946307Z"}}