Fedora Account System
Red Hat Associate
Red Hat Customer
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks. References: https://framework.zend.com/security/advisory/ZF2015-05
There is no version of package php-zendframework-zend-diactoros < 1.0.4 in any Fedora or EPEL repo. The first version of this package that was released in Fedora/EPEL was 1.1.2 and is currently at version 1.4.0. See https://bodhi.fedoraproject.org/updates/?search=php-zendframework-zend-diactoros