[GHSA-hhpq-7wg4-36jm] CakePHP Authentication: Open redirect weakness via backslash bypass - #8937
Conversation
|
Hi there @markstory! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
I've opened a similar pull request in #8485. This change doesn't narrow the opening version range for the 3.x releases, so 2.x would still be counted as vulnerable. |
|
I had completely overlooked that pull request, but my intention was exactly the same: I wanted to update the vulnerability information that was interfering with installation via Composer. Once #8485 is merged, the objective will be achieved. |
Updates
Comments
The patch for
2.xwas released later.References