Tags: cakephp/cache
Tags
[Security] Add allowedClasses config to RedisEngine to prevent PHP Ob… …ject Injection (#19485) * security: add allowedClasses config to prevent PHP Object Injection in cache unserialize() RedisEngine and FileEngine both call unserialize() on data fetched from their respective backends without restricting the allowed_classes option. An attacker who can write to the cache backend (e.g., via a compromised Redis instance, APC race, or a cache-poisoning vulnerability in the application) can trigger PHP Object Injection by injecting a crafted serialized payload containing a gadget chain. Add an 'allowedClasses' configuration option (default: true = allow all, for backwards compatibility) to both engines. Applications that only cache scalar or array values can set 'allowedClasses' => false to eliminate the attack surface; applications caching known object types can enumerate only those classes. * revert FileEngine.php to master — only harden Redis/Memcache backends * Add test coverage for allowedClasses and fix failing config tests - Add the new allowedClasses key to the expected default config arrays in RedisEngineTest and RedisClusterEngineTest (the new option broke the testConfig / testConfigDsn / testConfigDsnSSLContext assertions). - Cover the allowedClasses behavior: default (true) unserializes objects, false yields incomplete class instances, an array whitelist allows only listed classes, and scalars/arrays round-trip in every mode. - Move the allowedClasses documentation into the class docblock option list to match the convention used for every other config key. --------- Co-authored-by: XananasX7 <xananasX7@users.noreply.github.com> Co-authored-by: Mark Scherer <dereuromark@users.noreply.github.com>
PreviousNext