SB2020012733 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Zend Framework
Published: January 27, 2020 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2015-3154)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
CRLF injection vulnerability in ZendMail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
Remediation
Install update from vendor's website.