CVE-2014-2681: XEE
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendServiceAudioScrobbler, ZendServiceNirvanix, ZendServiceSlideShare, ZendServiceTechnorati, and ZendServiceWindowsAzure before 2.0.2, ZendServiceAmazon before 2.0.3, and ZendServiceApi before 1.0.0 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2681?
CVE-2014-2681 is classified as a moderate severity vulnerability in various versions of Zend Framework.
How do I fix CVE-2014-2681?
To mitigate CVE-2014-2681, upgrade to Zend Framework version 1.12.4 or 2.1.6 and above, or ensure you're using the latest versions of the affected Zend services.
What software is affected by CVE-2014-2681?
CVE-2014-2681 affects numerous versions of Zend Framework, ZendRest, and various ZendService components.
Is CVE-2014-2681 exploitable?
Yes, CVE-2014-2681 is exploitable if the affected software is deployed without applying recommended security updates.
What are the implications of CVE-2014-2681?
The implications of CVE-2014-2681 may include security risks such as data exposure due to insufficient verification mechanisms in affected Zend components.