CVE-2021-3007

Source
https://cve.org/CVERecord?id=CVE-2021-3007
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3007.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3007
Aliases
Published
2021-01-04T03:15:13.527Z
Modified
2026-03-14T14:57:25.918723Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized

References

Affected packages

Git / github.com/laminas/laminas-http

Affected ranges

Type
GIT
Repo
https://github.com/laminas/laminas-http
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.14.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/zendframework/zendframework
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0"
        }
    ]
}

Affected versions

2.*
2.11.3
2.12.0
2.13.0
2.14.0
2.14.1
Other
last-docs-commit
release-2.*
release-2.0.0
release-2.0.0beta1
release-2.0.0beta2
release-2.0.0beta3
release-2.0.0beta4
release-2.0.0beta5
release-2.0.0dev1
release-2.0.0dev2
release-2.0.0dev4
release-2.0.0rc1
release-2.0.0rc2
release-2.0.0rc3
release-2.0.0rc4
release-2.0.0rc5
release-2.0.0rc6
release-2.0.0rc7
release-2.0.1
release-2.0.2
release-2.0.3
release-2.0.4
release-2.0.6
release-2.1.1
release-2.1.2
release-2.1.3
release-2.1.4
release-2.1.5
release-2.2.0
release-2.2.0rc1
release-2.2.0rc2
release-2.2.0rc3
release-2.2.1
release-2.2.2
release-2.2.3
release-2.2.4
release-2.2.5
release-2.2.6
release-2.3.0
release-2.3.1
release-2.3.2
release-2.3.3
release-2.3.4
release-2.3.5
release-2.3.6
release-2.3.7
release-2.4.0
release-2.4.1
release-2.4.2
release-2.5.0
release-2.5.1
release-2.5.2
release-2.5.3
release-3.*
release-3.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3007.json"