GHSA-r5pm-vrc5-3m73LowCVSS 3.7
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
🔗 CVE IDs covered (1)
📋 Description
Impact
For jobs with shouldBeUnique = true the queue plugin will generate a 'unique identifier' based on the job class, method and parameters. If user data is supplied, a malicious user could create collisions, resulting in legitimate jobs being dropped.
Patches
Upgrade to 2.3.1
Workarounds
You can disable shouldBeUnique and handle idempotency in application code.
🎯 Affected products1
- composer/cakephp/queue:>= 0.1.10, < 2.3.1