Zend\Db\Adapter\Platform\Postgresqlwas incorrectly using
\\to escape double quotes in identifiers and values, which could lead to SQL injection vectors. We have provided patches that use proper escaping. If you use Postgresql with Zend Framework 2, we recommend upgrading immediately.
$_SESSIONsuperglobal before session start, which meant the data was overwritten once the session began. This meant on subsequent calls, the validators had no data to compare against, making the sessions automatically valid. We have provided patches to ensure that validators are run only after the session has begun, which will ensure they validate sessions correctly going forward. If you use
Zend\Sessionvalidators, we recommend upgrading immediately.
Please login to add feedback.