CVE-2020-15400

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-15400
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15400.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-15400
Aliases
Related
Published
2020-06-30T12:15:12Z
Modified
2024-10-12T06:13:23.733216Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

References

Affected packages

Debian:11 / cakephp

Package

Name
cakephp
Purl
pkg:deb/debian/cakephp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.10.11-2.1
2.10.24-1
2.10.24-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/cakephp/cakephp

Affected ranges

Type
GIT
Repo
https://github.com/cakephp/cakephp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.3-dev
1.3.0
1.3.0-RC1
1.3.0-RC2
1.3.0-RC3
1.3.0-RC4
1.3.0-alpha
1.3.0-beta
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9

2.*

2.0.0
2.0.0-RC1
2.0.0-RC2
2.0.0-RC3
2.0.0-alpha
2.0.0-beta
2.0.0-dev
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0-RC
2.1.0-alpha
2.1.0-beta
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0-RC1
2.2.0-RC2
2.2.0-beta
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.3.0
2.3.0-RC1
2.3.0-RC2
2.3.0-beta
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.0-RC1
2.4.0-RC2
2.4.0-beta
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0-RC1
2.5.0-RC2
2.5.0-beta
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.6.0-RC1
2.6.0-beta

3.*

3.0.0
3.0.0-RC1
3.0.0-RC2
3.0.0-alpha1
3.0.0-alpha2
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-dev1
3.0.0-dev2
3.0.0-dev3
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0-RC1
3.1.0-beta
3.1.0-beta2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0-RC1
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.14
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0-RC1
3.3.0-beta
3.3.0-beta2
3.3.0-beta3
3.3.1
3.3.10
3.3.11
3.3.12
3.3.13
3.3.14
3.3.15
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.0-RC1
3.4.0-RC2
3.4.0-RC3
3.4.0-RC4
3.4.0-beta1
3.4.0-beta2
3.4.0-beta3
3.4.0-beta4
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0-RC1
3.5.0-RC2
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0-RC1
3.6.0-RC2
3.6.0-beta1
3.6.0-beta2
3.6.0-beta3
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
3.7.0
3.7.0-RC1
3.7.0-RC2
3.7.0-RC3
3.7.0-beta1
3.7.1
3.7.2
3.7.3
3.7.4
3.7.5
3.7.6
3.7.7
3.7.8
3.7.9
3.8.0
3.8.0-RC1
3.8.0-RC2
3.8.0-RC3
3.8.0-beta1
3.8.1
3.8.2
3.8.3
3.8.4
3.8.5
3.8.6
3.8.7
3.8.8

4.*

4.0.0
4.0.0-RC1
4.0.0-RC2
4.0.0-alpha1
4.0.0-alpha2
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5