GHSA-6hg4-vp5q-47mw

Suggest an improvement
Source
https://github.com/advisories/GHSA-6hg4-vp5q-47mw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-6hg4-vp5q-47mw/GHSA-6hg4-vp5q-47mw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6hg4-vp5q-47mw
Published
2023-01-20T23:34:05Z
Modified
2024-11-29T05:38:49.564107Z
Summary
CakePHP allows direct access of prefixed controller actions
Details

Unconventional URL paths would allow direct access to prefixed actions without setting the correct request parameters.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-01-20T23:34:05Z"
}
References

Affected packages

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.0.99

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1.0
Fixed
2.1.99

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2.0
Fixed
2.2.99

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.99

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.0
Fixed
2.4.99

Affected versions

2.*

2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.5.0
Fixed
2.5.9

Affected versions

2.*

2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.0
Fixed
2.6.11

Affected versions

2.*

2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.10

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.7.0
Fixed
2.7.2

Affected versions

2.*

2.7.0
2.7.1