CyberRota Analysis
AI-GeneratedThe CakePHP Authentication plugin is vulnerable to authentication bypass and potential CPU or memory exhaustion due to the use of unencrypted, forgeable legacy tokens in versions prior to 2.11.2, 3.0.0 through 3.3.6, and 4.0.0 through 4.2.0. This critical vulnerability can compromise application security and lead to resource exhaustion, making it imperative for developers and system administrators using affected versions to prioritize upgrading to the patched releases 2.11.2, 3.3.7, or 4.2.1.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.