icon

We found results for “

WS-2018-0158

Good to know:

icon

Date: August 1, 2018

URL Rewrite vulnerability in zendframework which is exist in projects zend-diactoros before version 1.8.4, in zend-http before version 2.8.1 and in zend-feed before version 2.10.3. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

URL Redirection to Untrusted Site ('Open Redirect')

CWE-601

Top Fix

icon

Upgrade Version

Upgrade to version drupal/drupal - 8.0.0;drupal/drupal - 8.1.0-beta2;drupal/drupal - 8.0.0-rc2;drupal/drupal - 8.0.0-beta2;drupal/drupal - 8.0.1;limesurvey/limesurvey - 3.27.28+211208;limesurvey/limesurvey - 2.65.2+170606;limesurvey/limesurvey - 3.27.33+220125;limesurvey/limesurvey - 4.4.0+210129;limesurvey/limesurvey - dev-fixv3-16987;limesurvey/limesurvey - no_fix;limesurvey/limesurvey - 3.23.5+200923;limesurvey/limesurvey - dev-clicks-test3;limesurvey/limesurvey - dev-revert-14-scrutinizer-patch-1;limesurvey/limesurvey - dev-survey-defaultsettings;limesurvey/limesurvey - 3.0.1+171228;limesurvey/limesurvey - dev-redo-13161;limesurvey/limesurvey - dev-survey-booleans3;limesurvey/limesurvey - dev-fix-tests;limesurvey/limesurvey - dev-fix-16987;limesurvey/limesurvey - dev-booleans1;limesurvey/limesurvey - 4.0.0-alpha+181212;limesurvey/limesurvey - dev-viewanswers;limesurvey/limesurvey - 4.0.0-RC2+190723;limesurvey/limesurvey - 5.0.1+210532;limesurvey/limesurvey - dev-snyk-upgrade-66feccfba764223474d4b09ea736da24;limesurvey/limesurvey - 3.27.35+220208;limesurvey/limesurvey - 6.0.1+230411;limesurvey/limesurvey - 3.28.18+220706;limesurvey/limesurvey - dev-inspect34;limesurvey/limesurvey - dev-snyk-upgrade-8e8193a6a781d5929de6292963cd2a21;limesurvey/limesurvey - 3.28.14+220608;limesurvey/limesurvey - dev-tests-clieck-views1;zendframework/zend-diactoros - 1.8.4;zendframework/zend-diactoros - dev-release-1.8;zendframework/zend-feed - 2.1.5;zendframework/zend-feed - 2.0.7;zendframework/zend-feed - 2.2.6;zendframework/zend-feed - 2.10.3;zendframework/zend-feed - 2.1.2;zendframework/zend-feed - 2.2.0rc3;zendframework/zend-feed - 2.2.3;zendframework/zend-feed - 2.3.4;zendframework/zend-feed - dev-master;zendframework/zend-feed - 2.4.1;zendframework/zend-feed - 2.4.0rc3;zendframework/zend-feed - 2.0.4;vufind/vufind - v1.28.0;vufind/vufind - dev-release-3.0;vufind/vufind - dev-legacy/clavius;vufind/vufind - v1.23.0;vufind/vufind - dev-demiankatz-patch-1;vufind/vufind - dev-VUFIND-1342;vufind/vufind - v1.20.0;vufind/vufind - dev-autocomplete-v2-1-10;lochmueller/autoloader - dev-analysis-3wWO14;lochmueller/autoloader - 3.2.0;pi/pi - no_fix;pi/pi - v2.8.0;muse/zend-diactoros - dev-release-1.8;muse/zend-diactoros - 1.8.4;zendframework/zend-http - 2.4.8;zendframework/zend-http - 2.1.5;zendframework/zend-http - 2.4.2;zendframework/zend-http - 2.2.6;zendframework/zend-http - 2.4.0rc3;zendframework/zend-http - 2.8.1;zendframework/zend-http - 2.0.7;zendframework/zend-http - 2.3.5;zendframework/zend-http - 2.1.2;zendframework/zend-http - dev-master;zendframework/zend-http - 2.4.0rc6;zendframework/zend-http - 2.2.3;zendframework/zend-http - 2.2.0rc3;zendframework/zend-http - 2.3.2;openwebapp/openwebapp - no_fix;reliv/rcm-dynamic-navigation - 0.1.2;controleonline/speed-up-essentials - no_fix;controleonline/speed-up-essentials - v1.0.0;xtreed/zend-diactoros - dev-release-1.8;xtreed/zend-diactoros - 1.8.4;vijaycs85/coverage-report - 8.1.0-beta2;torrentpier/torrentpier - v2.2.0;obimet/tool_console - no_fix;drupal/core-render - 8.1.0;zzh-php/lib - no_fix;boboldehampsink/pushnotifications - no_fix;boboldehampsink/pushnotifications - 0.0.3;boboldehampsink/pushnotifications - dev-feature/mpns;drupal/core-dependency-injection - 8.0.0-beta15;drupal/core-dependency-injection - 8.0.0-rc1;drupal/core-file-cache - 8.1.0;thxyh99/composer_advance - no_fix;withadresden/superdrupal - no_fix;serkancelik17/hotel_content_api_sdk - no_fix;webflo/drupal - no_fix;drupal/core - 8.0.0-beta16;drupal/core - 8.0.0-rc1;vivaweb/zendframework - 2.5.0;rcm/dynamic-navigation - 0.1.2;atnightandintransportation/cms - 0.6.1;gotcms/gotcms - no_fix;gotcms/gotcms - 0.1.0a;redactivemedia/redactive-drupal8-platform - 8.8.0;sos-solution/other-framework - no_fix;tanzhenxing/educms - 1.06;drupal/core-assertion - 8.1.0;fatfish/importer - v1.0;zendframework/zendframework - 2.5.0;drupal/core-http-foundation - 8.1.0;thxyh99/zendframework - no_fix;cristiroma/drupal-boilerplate-8 - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us