MGASA-2016-0044
Dashboard / Vulnerabilities / MGASA-2016-0044
MGASA-2016-0044
Published: 5 Feb 2016Last Modified: 16 Apr 2026
Summary: Updated cakephp package fixes security vulnerability
Details: CakePHP, an open-source web application framework for PHP, was vulnerable to SSRF (Server Side Request Forgery) attacks. Remote attacker can utilize it for at least DoS (Denial of Service) attacks, if the target application accepts XML as an input. It is caused by insecure design of Cake's Xml class.
References: https://advisories.mageia.org/MGASA-2016-0044.html, https://bugs.mageia.org/show_bug.cgi?id=17003, http://lwn.net/Alerts/661886/
Affected packages
Package
Name: cakephp
Purl: pkg:rpm/mageia/cakephp?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.3.21-2.mga5
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
