{"id":"GHSA-q79m-c546-2g63","aliases":[],"url":"https://o3.security/vulnerability/GHSA-q79m-c546-2g63","summary":"CakePHP vulnerable to Denial of Service attack through XML payloads","details":"RequestHandlerComponent had a vulnerability that would allow well crafted requests to create a denial of service attack. RequestHandlerComponent leverages `Xml::build()` which allows reading local files. We recommend that all applications using RequestHandlerComponent upgrade, or disable parsing XML payloads.","published":"2023-01-20T23:23:26Z","modified":"2024-11-29T05:40:08.569689Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"3.0.6"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.0.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.1.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.2.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.3.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.4.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.5.90"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.6.6"}],"fix":{"url":"https://github.com/cakephp/cakephp/commit/c186487151356a8d7c6e2cae05f87b9df0e59fbb","label":"cakephp/cakephp@c186487"},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/commit/c186487151356a8d7c6e2cae05f87b9df0e59fbb"},{"type":"WEB","url":"https://bakery.cakephp.org/2015/05/28/cakephp_2_6_6_and_3_0_6_released.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cakephp/cakephp/2015-05-28.yaml"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:40:08.569689Z"}}