Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2014-2685

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

  • Published: Sep 4, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-2685
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software From Fixed in
zend / zend_framework 1.10.6 1.10.6.x
zend / zend_framework 1.10.0-beta1 1.10.0-beta1.x
zend / zend_framework 1.12.0-rc3 1.12.0-rc3.x
zend / zend_framework 1.11.0-b1 1.11.0-b1.x
zend / zend_framework 1.10.3 1.10.3.x
zend / zend_framework 1.11.4 1.11.4.x
zend / zend_framework 1.7.4 1.7.4.x
zend / zend_framework 1.7.5 1.7.5.x
zend / zend_framework 1.10.5 1.10.5.x
zend / zend_framework 1.11.11 1.11.11.x
zend / zend_framework 1.10.8 1.10.8.x
zend / zend_framework 1.12.2 1.12.2.x
zend / zend_framework 1.10.0 1.10.0.x
zend / zend_framework 1.5.0 1.5.0.x
zend / zend_framework 1.9.6 1.9.6.x
zend / zend_framework 1.10.0-alpha1 1.10.0-alpha1.x
zend / zend_framework 1.8.3 1.8.3.x
zend / zend_framework 1.7.6 1.7.6.x
zend / zend_framework 1.5.0-pr 1.5.0-pr.x
zend / zend_framework 1.8.0 1.8.0.x
zend / zend_framework 1.11.5 1.11.5.x
zend / zend_framework 1.8.4-pl1 1.8.4-pl1.x
zend / zend_framework 1.11.0-rc1 1.11.0-rc1.x
zend / zend_framework 1.7.2 1.7.2.x
zend / zend_framework 1.0.0-rc2a 1.0.0-rc2a.x
zend / zend_framework 1.5.0-rc1 1.5.0-rc1.x
zend / zend_framework 1.6.0 1.6.0.x
zend / zend_framework 1.9.0-rc1 1.9.0-rc1.x
zend / zend_framework 1.7.0-pr 1.7.0-pr.x
zend / zend_framework 1.9.2 1.9.2.x
zend / zend_framework 1.11.12 1.11.12.x
zend / zend_framework 1.9.3 1.9.3.x
zend / zend_framework 1.5.1 1.5.1.x
zend / zend_framework 1.10.4 1.10.4.x
zend / zend_framework 1.6.0-rc2 1.6.0-rc2.x
zend / zend_framework 1.11.9 1.11.9.x
zend / zend_framework 1.0.0-rc2 1.0.0-rc2.x
zend / zend_framework 1.8.4 1.8.4.x
zend / zend_framework 1.11.6 1.11.6.x
zend / zend_framework 1.8.1 1.8.1.x
zend / zend_framework 1.9.5 1.9.5.x
zend / zend_framework 1.6.0-rc3 1.6.0-rc3.x
zend / zend_framework 1.9.0-b1 1.9.0-b1.x
zend / zend_framework 1.9.0-a1 1.9.0-a1.x
zend / zend_framework 1.0.0 1.0.0.x
zend / zend_framework 1.11.3 1.11.3.x
zend / zend_framework 1.5.0-rc3 1.5.0-rc3.x
zend / zend_framework 1.5.0-rc2 1.5.0-rc2.x
zend / zend_framework 1.11.13 1.11.13.x
zend / zend_framework 1.5.2 1.5.2.x
zend / zend_framework 1.11.2 1.11.2.x
zend / zend_framework 1.9.0 1.9.0.x
zend / zend_framework 1.0.0-rc3 1.0.0-rc3.x
zend / zend_framework 1.0.3 1.0.3.x
zend / zend_framework 1.9.8 1.9.8.x
zend / zend_framework 1.10.0-rc1 1.10.0-rc1.x
zend / zend_framework 1.11.0 1.11.0.x
zend / zend_framework 1.11.10 1.11.10.x
zend / zend_framework 1.6.1 1.6.1.x
zend / zend_framework 1.9.7 1.9.7.x
zend / zend_framework 1.6.2 1.6.2.x
zend / zend_framework 1.9.3-pl1 1.9.3-pl1.x
zend / zend_framework 1.12.1 1.12.1.x
zend / zend_framework 1.7.3-pl1 1.7.3-pl1.x
zend / zend_framework 1.12.0-rc1 1.12.0-rc1.x
zend / zend_framework 1.0.0-rc1 1.0.0-rc1.x
zend / zend_framework 1.7.0 1.7.0.x
zend / zend_framework 1.10.1 1.10.1.x
zend / zend_framework 1.12.0-rc4 1.12.0-rc4.x
zend / zend_framework 1.8.5 1.8.5.x
zend / zend_framework 1.8.2 1.8.2.x
zend / zend_framework 1.11.8 1.11.8.x
zend / zend_framework 1.7.1 1.7.1.x
zend / zend_framework 1.7.7 1.7.7.x
zend / zend_framework 1.6.0-rc1 1.6.0-rc1.x
zend / zend_framework 1.9.1 1.9.1.x
zend / zend_framework 1.8.0-b1 1.8.0-b1.x
zend / zend_framework 1.10.7 1.10.7.x
zend / zend_framework 1.10.9 1.10.9.x
zend / zend_framework 1.11.7 1.11.7.x
zend / zend_framework 1.7.9 1.7.9.x
zend / zend_framework 1.0.1 1.0.1.x
zend / zend_framework 1.5.0-pl 1.5.0-pl.x
zend / zend_framework 1.12.0-rc2 1.12.0-rc2.x
zend / zend_framework - 1.12.3.x
zend / zend_framework 1.7.0-pl1 1.7.0-pl1.x
zend / zend_framework 1.10.2 1.10.2.x
zend / zend_framework 1.7.3 1.7.3.x
zend / zend_framework 1.11.1 1.11.1.x
zend / zend_framework 1.0.4 1.0.4.x
zend / zend_framework 1.0.2 1.0.2.x
zend / zend_framework 1.8.0-a1 1.8.0-a1.x
zend / zend_framework 1.7.8 1.7.8.x
zend / zend_framework 1.9.4 1.9.4.x
zend / zend_framework 1.5.3 1.5.3.x
zend / zend_framework 1.12.0 1.12.0.x
zend / zendopenid - 2.0.1.x