CVE-2014-2685
CVE-2014-2685 is a high-severity vulnerability in Zend Zend Framework with a CVSS 2.0 base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 3% (86th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Zend Zend Framework
- Published:
- Last modified:
Description
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Frequently asked questions
- What is CVE-2014-2685?
- The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
- How severe is CVE-2014-2685?
- CVE-2014-2685 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2014-2685 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (86th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-2685?
- CVE-2014-2685 primarily affects Zend Zend Framework. In total, 97 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2014-2685?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2014-2685 published?
- CVE-2014-2685 was published on 2014-09-04 and last updated on 2026-06-17.
References
- http://advisories.mageia.org/MGASA-2014-0151.html
- http://framework.zend.com/security/advisory/ZF2014-02
- http://seclists.org/oss-sec/2014/q2/0
- http://www.debian.org/security/2015/dsa-3265
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:072
- http://www.securityfocus.com/bid/66358
Affected products (97)
- cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.0:rc2a:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.0:pl:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.0:pr:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.6.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.6.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.6.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.0:pl1:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.0:pr:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.3:pl1:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.5:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.6:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.7:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.8:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.7.9:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:zend:zend_framework:1.8.0:a1:*:*:*:*:*:*
More vulnerabilities in Zend Zend Framework
- CVE-2020-29312 — Critical (CVSS 9.8): An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the…
- CVE-2021-3007 — Critical (CVSS 9.8): Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead…
- CVE-2014-8089 — Critical (CVSS 9.8): SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the…
- CVE-2011-1939 — Critical (CVSS 9.8): SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using…
- CVE-2014-4914 — Critical (CVSS 9.8): The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows…
- CVE-2016-6233 — Critical (CVSS 9.8): The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers…
All CVEs affecting Zend Zend Framework →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →