CVE-2019-11458: High severity cakephp vulnerability
Published Apr 20, 2019
·Updated
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.
Affected Software
6 affected componentsFixes available
composer/cakephp/cakephp>=3.0.0, <3.5.18, >=3.6.0, <3.6.15, >=3.7.0, <3.7.7
Cakefoundation Cakephp=3.7.6
CakePHP CakePHP=3.7.6
composer/cakephp/cakephp>=3.7.0<3.7.7
3.7.7
composer/cakephp/cakephp>=3.6.0<3.6.15
3.6.15
composer/cakephp/cakephp>=3.0.0<3.5.18
3.5.18
Remediation
Patch Available
Patch Available
Event History
Apr 20, 2019
Advisory Published
10:08 PM
May 8, 2019
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11458?
CVE-2019-11458 has a high severity level due to the potential for arbitrary file overwriting.
2
How do I fix CVE-2019-11458?
To fix CVE-2019-11458, upgrade SmtpTransport to CakePHP version 3.7.7, 3.6.15, or 3.5.18.
3
What versions of CakePHP are affected by CVE-2019-11458?
CVE-2019-11458 affects CakePHP versions from 3.0.0 up to 3.7.6, including certain 3.6.x and 3.5.x versions.
4
What is the impact of CVE-2019-11458?
The impact of CVE-2019-11458 allows an attacker to overwrite arbitrary files through unsafe deserialization.
5
Is CVE-2019-11458 publicly known?
Yes, CVE-2019-11458 was publicly disclosed and documented in various security advisories.