V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-3007
CVE
CriticalConfirmedExploit available

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code exec…

CVSS
9.8
Critical
EPSS
0.75
p99
Published
2021-01-01
Updated
2021-01-01
Description

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized

Tags · CWE
Pre-auth
CWE-502
CAPEC-586
Affected products
Laminas-http < 2.14.2Zend_framework
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.753 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2021-3007
github-poc · https://github.com/KrE80r/cve-2021-3007-vulnerable
Enterprise
Affected products
ProductVendorStatus
laminas-http*Tracked
zend_framework*Tracked
Source databases
CVE