{"id":"GHSA-848f-mph5-9pm9","summary":"Zendframework Potential Information Disclosure and Insufficient Entropy vulnerability","details":"In Zend Framework, Zend_Captcha_Word (v1) and Zend\\Captcha\\Word (v2) generate a \"word\" for a CAPTCHA challenge by selecting a sequence of random letters from a character set. Prior to this advisory, the selection was performed using PHP's internal array_rand() function. This function does not generate sufficient entropy due to its usage of rand() instead of more cryptographically secure methods such as openssl_pseudo_random_bytes(). This could potentially lead to information disclosure should an attacker be able to brute force the random number generation.","modified":"2024-12-04T05:39:36.296019Z","published":"2024-06-07T22:27:02Z","database_specific":{"cwe_ids":["CWE-331"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-06-07T22:27:02Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2015-09"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/ZF2015-09.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zf1"}],"affected":[{"package":{"name":"zendframework/zendframework1","ecosystem":"Packagist","purl":"pkg:composer/zendframework/zendframework1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.12.0"},{"fixed":"1.12.17"}]}],"versions":["1.12.0","1.12.1","1.12.10","1.12.11","1.12.12","1.12.13","1.12.14","1.12.15","1.12.16","1.12.2","1.12.3","1.12.4","1.12.5","1.12.6","1.12.7","1.12.8","1.12.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-848f-mph5-9pm9/GHSA-848f-mph5-9pm9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}