Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m496-x567-f98c

Опубликовано: 22 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Fixes a bug in Zend Framework's Stream HTTP Wrapper

Impact

CVE-2021-3007: Backport of Zend_Http_Response_Stream, added certain type checking as a way to prevent exploitation. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3007

This vulnerability is caused by the unsecured deserialization of an object. In versions higher than Zend Framework 3.0.0, the attacker abuses the Zend3 feature that loads classes from objects in order to upload and execute malicious code in the server. The code can be uploaded using the “callback” parameter, which in this case inserts a malicious code instead of the “callbackOptions” array.

Patches

Has the problem been patched? What versions should users upgrade to? v20.0.9 v19.4.13

Пакеты

Наименование

openmage/magento-lts

composer
Затронутые версииВерсия исправления

<= 19.4.12

19.4.13

Наименование

openmage/magento-lts

composer
Затронутые версииВерсия исправления

>= 20.0.0, <= 20.0.8

20.0.9

EPSS

Процентиль: 60%
0.00405
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 and 20.0.9 was back ported from Zend Framework 3. The vulnerability was assigned CVE-2021-3007 in Zend Framework.

EPSS

Процентиль: 60%
0.00405
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502