Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mg7h-9qfx-4r83

Опубликовано: 07 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

ZendFramework Potential Proxy Injection Vulnerabilities

Zend\Session\Validator\RemoteAddr and Zend\View\Helper\ServerUrl were found to be improperly parsing HTTP headers for proxy information, which could potentially allow an attacker to spoof a proxied IP or host name.

In Zend\Session\Validator\RemoteAddr, if the client is behind a proxy server, the detection of the proxy URL was incorrect, and could lead to invalid results on subsequent lookups.

In Zend\View\Helper\ServerUrl, if the server lives behind a proxy, the helper would always generate a URL based on the proxy host, regardless of whether or not this was desired; additionally, it did not take into account the proxy port or protocol, if provided.

Пакеты

Наименование

zendframework/zendframework

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.5

2.0.5

5.9 Medium

CVSS3

Дефекты

CWE-74

5.9 Medium

CVSS3

Дефекты

CWE-74