CVE-2012-3363

critical
Published 2013-02-13 · Modified 2024-04-09
CVSS v3
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v2
6.4
VIR risk
9.1

Description

Zend Framework XXE Vulnerability

Predictions

Exploit likelihood
94%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://framework.zend.com/security/advisory/ZF2012-01

OS impact

OSVersionStatusFixed in
fedora fedora17affected
fedora fedora18affected
debian debian6.0affected

Package impact

EcosystemPackageVulnerableFixed
php Packagistzendframework/zendframework1>=1.0.0,<1.11.121.11.12
php Packagistzendframework/zendframework1>=1.12.0-rc1,<1.12.01.12.0

Application impact

VendorProductVersionsFixed
zendzend_framework{"startIncluding":"1.0.0","endExcluding":"1.11.12"}1.11.12
zendzend_framework1.12.0

References

CWEs

CWE-611

Verify integrity in audit chain (admin only). AS-IS.