GHSA-5qp6-78pr-gv8c

Suggest an improvement
Source
https://github.com/advisories/GHSA-5qp6-78pr-gv8c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5qp6-78pr-gv8c/GHSA-5qp6-78pr-gv8c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5qp6-78pr-gv8c
Aliases
  • CVE-2013-4701
Published
2022-05-17T03:46:28Z
Modified
2024-12-02T05:39:53.259051Z
Summary
PHP OpenID Library Denial of Service vulnerability
Details

Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Database specific
{
    "nvd_published_at": "2013-08-21T16:55:00Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-08-29T18:03:31Z"
}
References

Affected packages

Packagist / openid/php-openid

Package

Name
openid/php-openid
Purl
pkg:composer/openid/php-openid

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.0

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.6

Affected versions

6.*

6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5