CVE-2014-2684
16.11.2014, 00:59
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity Provider as the provider used in the association handle, which allows remote attackers to bypass authentication and spoof arbitrary OpenID identities by using a malicious OpenID Provider that generates OpenID tokens with arbitrary identifier and claimed_id values.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zend | zendopenid | 𝑥 ≤ 2.0.1 |
| zend | zend_framework | 𝑥 ≤ 1.12.4 |
𝑥
= Vulnerable software versions
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| php-ZendFramework |
| ||
| php-ZendFramework-Auth-Adapter-Ldap |
| ||
| php-ZendFramework-Cache-Backend-Apc |
| ||
| php-ZendFramework-Cache-Backend-Libmemcached |
| ||
| php-ZendFramework-Cache-Backend-Memcached |
| ||
| php-ZendFramework-Captcha |
| ||
| php-ZendFramework-Db-Adapter-Mysqli |
| ||
| php-ZendFramework-Db-Adapter-Pdo |
| ||
| php-ZendFramework-Db-Adapter-Pdo-Mssql |
| ||
| php-ZendFramework-Db-Adapter-Pdo-Mysql |
| ||
| php-ZendFramework-Db-Adapter-Pdo-Pgsql |
| ||
| php-ZendFramework-Dojo |
| ||
| php-ZendFramework-Feed |
| ||
| php-ZendFramework-Ldap |
| ||
| php-ZendFramework-Pdf |
| ||
| php-ZendFramework-Search-Lucene |
| ||
| php-ZendFramework-Serializer-Adapter-Igbinary |
| ||
| php-ZendFramework-Services |
| ||
| php-ZendFramework-Soap |
| ||
| php-ZendFramework-demos |
| ||
| php-ZendFramework-extras |
| ||
| php-ZendFramework-full |
|
Common Weakness Enumeration
References