CVE-2021-3007 is a critical deserialization vulnerability affecting Laminas Project laminas-http (before 2.14.2) and Zend Framework 3.0.0, stemming from the __destruct method of the Zend\Http\Response\Stream class. This flaw allows for remote code execution if an attacker can control the content being deserialized. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit intelligence shows available Nuclei templates and significant community discussion and media coverage, including reports of its exploitation by the FreakOut malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.14.2CPE matchmatch criteria | cpe:2.3:a:getlaminas:laminas-http:*:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:zend:zend_framework:3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.