{"id":"GHSA-q79m-c546-2g63","summary":"CakePHP vulnerable to Denial of Service attack through XML payloads","details":"RequestHandlerComponent had a vulnerability that would allow well crafted requests to create a denial of service attack. RequestHandlerComponent leverages `Xml::build()` which allows reading local files. We recommend that all applications using RequestHandlerComponent upgrade, or disable parsing XML payloads.","modified":"2024-11-29T05:40:08.569689Z","published":"2023-01-20T23:23:26Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-01-20T23:23:26Z"},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/commit/c186487151356a8d7c6e2cae05f87b9df0e59fbb"},{"type":"WEB","url":"https://bakery.cakephp.org/2015/05/28/cakephp_2_6_6_and_3_0_6_released.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cakephp/cakephp/2015-05-28.yaml"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"}],"affected":[{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.6"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.99"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.99"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.99"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.99"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.4.99"}]}],"versions":["2.4.10","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.5.90"}]}],"versions":["2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.5.7","2.5.8","2.5.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.6.6"}]}],"versions":["2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-q79m-c546-2g63/GHSA-q79m-c546-2g63.json"}}],"schema_version":"1.9.0"}