Movatterモバイル変換


[0]ホーム

URL:


Zend Framework

Security

Security Advisory: ZF2018-01

ZF2018-01: URL Rewrite vulnerability

zend-diactoros (and, byextension,Expressive),zend-http (and, by extension,Zend Framework MVC projects),andzend-feed (specifically, itsPubSubHubbub sub-component) each contain a potential URL rewrite exploit. Ineach case, marshaling a request URI includes logic that introspects HTTP requestheaders that are specific to a given server-side URL rewrite mechanism.

When these headers are present on systems not running the specific URL rewritingmechanism, the logic would still trigger, allowing a malicious client or proxyto emulate the headers to request arbitrary content.

Action Taken

In each of the affected components, we have removed support for the specificrequest headers. Users can provide support within their applications tore-instate the logic if they are using the specific URL rewrite mechanism; usersare encouraged to filter these headers in their web server prior to any rewritesto ensure their validity.

The patch resolving the vulnerability is available in:

  • zend-diactoros, 1.8.4
  • zend-http, 2.8.1
  • zend-feed, 2.10.3

Zend Framework MVC, Apigility, and Expressive users will receive relevantupdated components viacomposer update.

We highly recommend all users of affected projects update immediately.

Acknowledgments

The Zend Framework team thanks the following for identifying the issues andworking with us to help protect its users:

Released 2018-08-01

Back to advisories

Have you identified a security vulnerability?

Please report it to us atzf-security@zend.com

About
Overview
FAQ
License
Changelog
Security
Issues

Install
Get started
MVC skeleton app
Expressive skeleton app
Archives

Documentation
Overview
Training and Certification
Support and Consulting
Webinars
Blog
Zend Framework 2 -API
Zend Framework 1 -API

Participate
Overview
Slack
Forums
Contributor guide
Code Manifesto
Contributors
Logos
Get certified
Privacy Policy

Copyright

© 2006-2022 byZend byPerforce. Made with by awesomecontributors.

This website is built usingzend-expressive and it runs onPHP 7.

Contacts


[8]ページ先頭

©2009-2025 Movatter.jp