Zend Framework Authentication Bypass Vulnerability (CVE-2014-8088)
Release date:
Updated on:
Affected Systems:
Zend Framework 2.3.3
Zend Framework 2.2.8
Zend Framework 1.12.9
Description:
Bugtraq id: 70378
CVE (CAN) ID: CVE-2014-8088
Zend Framework (ZF) is an open-source PHP5 development Framework that can be used to develop web programs and services.
Zend Framework 1.12.9, 2.2.8, and 2.3.3 have the identity verification Bypass Vulnerability. Attackers can exploit this vulnerability to bypass the authentication mechanism and obtain unauthorized access permissions.
<* Source: Matthew Daley
*>
Suggestion:
Vendor patch:
Zend
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://framework.zend.com/security/advisory/ZF2014-05
Http://framework.zend.com/blog/zend-framework-1-12-9-2-2-8-and-2-3-3-released.html
This article permanently updates the link address: