{"id":"GHSA-96c6-m98x-hxjx","summary":"Zend-Session session validation vulnerability","details":"`Zend\\Session` session validators do not work as expected if set prior to the start of a session.\n\nFor instance, the following test case fails (where $this-\u003emanager is an instance of `Zend\\Session\\SessionManager`):\n```\n$this\n    -\u003emanager\n    -\u003egetValidatorChain()\n    -\u003eattach('session.validate', array(new RemoteAddr(), 'isValid'));\n\n$this-\u003emanager-\u003estart();\n\n$this-\u003eassertSame(\n    array(\n        'Zend\\Session\\Validator\\RemoteAddr' =3D\u003e '',\n    ),\n    $_SESSION['__ZF']['_VALID']\n);\n```\nThe implication is that subsequent calls to `Zend\\Session\\SessionManager#start()` (in later requests, assuming a session was created) will not have any validator metadata attached, which causes any validator metadata to be re-built from scratch, thus marking the session as valid.\n\nAn attacker is thus able to simply ignore session validators such as `RemoteAddr` or `HttpUserAgent`, since the \"signature\" that these validators check against is not being stored in the session.","modified":"2024-12-04T05:40:26.255578Z","published":"2024-06-07T21:25:23Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-06-07T21:25:23Z","nvd_published_at":null,"cwe_ids":["CWE-384"]},"references":[{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/05fa95488b5ade513c4dcc56051a7ddb1c94f341"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/1272fc047121720130690c324413629d8f63d210"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/35014ab0ae17c2a169320f182697ee9fe73d841e"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/3b1a65b3193a4219f5c4259ab8735f9ad254a021"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/6a27a9fddd8f5b12b3af0de6309181ff5946dd0e"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/7c4b73dd64e01001946aac76c6deddfe1c6ef0be"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/7fc94bd6a60342416242a3899d63072c471b33d3"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/93b43aa0ca5348d29034f67195ffa3f4082878d5"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/9868f84513536446b0bac81cc95e0130b0a6fc9c"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/a3382bfd3067f527762294b5fc622550988e6862"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/b1903947e285568344b3458e4524b016ce311072"},{"type":"WEB","url":"https://github.com/zendframework/zend-session/commit/ff9236cc4c4944b5f5a6fbfee01420ef82c4fa91"},{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2015-01"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-session/ZF2015-01.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zend-session"}],"affected":[{"package":{"name":"zendframework/zend-session","ecosystem":"Packagist","purl":"pkg:composer/zendframework/zend-session"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.2.9"}]}],"versions":["2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.2.0","2.2.0rc1","2.2.0rc2","2.2.0rc3","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-96c6-m98x-hxjx/GHSA-96c6-m98x-hxjx.json"}},{"package":{"name":"zendframework/zend-session","ecosystem":"Packagist","purl":"pkg:composer/zendframework/zend-session"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.4"}]}],"versions":["2.3.0","2.3.1","2.3.2","2.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-96c6-m98x-hxjx/GHSA-96c6-m98x-hxjx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}