CVE-2014-2684

UnknownEPSS 1.60%

Last modified

CVE-2014-2684 is a vulnerability of currently unknown severity. The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity Provider as the provider used in the association handle, which allows remote attackers to bypass authentication and spoof arbitrary OpenID identities by using a malicious OpenID Provider that generates OpenID tokens with arbitrary identifier and claimed_id values.. EPSS estimates a 1.60% chance of exploitation in the next 30 days.

Description

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity Provider as the provider used in the association handle, which allows remote attackers to bypass authentication and spoof arbitrary OpenID identities by using a malicious OpenID Provider that generates OpenID tokens with arbitrary identifier and claimed_id values.

Metrics

EPSS Probability
1.60%

72.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZendZendopenid<= 2.0.1
ZendZend Framework<= 1.12.4

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-2684?
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity Provider as the provider used in the association handle, which allows remote attackers to bypass authentication and spoof arbitrary OpenID identities by using a malicious OpenID Provider that generates OpenID tokens with arbitrary identifier and claimed_id values.
How severe is CVE-2014-2684?
Severity scoring for CVE-2014-2684 is pending analysis. The EPSS model estimates a 1.60% probability of exploitation in the next 30 days.
How do I fix CVE-2014-2684?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-2684?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST