Advisories ยป MGASA-2016-0044

Updated cakephp package fixes security vulnerability

Publication date: 05 Feb 2016
Modification date: 05 Feb 2016
Type: security
Affected Mageia releases : 5

Description

CakePHP, an open-source web application framework for PHP, was vulnerable
to SSRF (Server Side Request Forgery) attacks. Remote attacker can utilize
it for at least DoS (Denial of Service) attacks, if the target application
accepts XML as an input. It is caused by insecure design of Cake's Xml
class.
                

References

SRPMS

5/core