Sitelet https://github.com/cakephp/cache/tags
Skip to content

Tags: cakephp/cache

Tags

5.4.3

Toggle 5.4.3's commit message
Fix RedisEngine TLS options silently ignored (#19611) (#19612)

Fix RedisEngine TLS options silenty ignored (#19611)

Replaces `ssl` context option key with correct `stream` key.

5.4.2

Toggle 5.4.2's commit message
Fix RedisEngine TLS options silently ignored (#19611) (#19612)

Fix RedisEngine TLS options silenty ignored (#19611)

Replaces `ssl` context option key with correct `stream` key.

5.4.1

Toggle 5.4.1's commit message
Add missing add() method to NullEngine to prevent undefined prefix ke…

…y error (#19568)

Fix NullEngine::init() to call parent and initialize _config defaults

5.4.0

Toggle 5.4.0's commit message
Update version constraints and branch aliases

Update split package version constraints and branch aliases to 5.5

5.4.0-RC2

Toggle 5.4.0-RC2's commit message
Merge branch '5.x' into 5.next

5.3.7

Toggle 5.3.7's commit message
[Security] Add allowedClasses config to RedisEngine to prevent PHP Ob…

…ject Injection (#19485)

* security: add allowedClasses config to prevent PHP Object Injection in cache unserialize()

RedisEngine and FileEngine both call unserialize() on data fetched from their
respective backends without restricting the allowed_classes option. An attacker
who can write to the cache backend (e.g., via a compromised Redis instance,
APC race, or a cache-poisoning vulnerability in the application) can trigger
PHP Object Injection by injecting a crafted serialized payload containing a
gadget chain.

Add an 'allowedClasses' configuration option (default: true = allow all, for
backwards compatibility) to both engines. Applications that only cache scalar
or array values can set 'allowedClasses' => false to eliminate the attack
surface; applications caching known object types can enumerate only those
classes.

* revert FileEngine.php to master — only harden Redis/Memcache backends

* Add test coverage for allowedClasses and fix failing config tests

- Add the new allowedClasses key to the expected default config arrays in
  RedisEngineTest and RedisClusterEngineTest (the new option broke the
  testConfig / testConfigDsn / testConfigDsnSSLContext assertions).
- Cover the allowedClasses behavior: default (true) unserializes objects,
  false yields incomplete class instances, an array whitelist allows only
  listed classes, and scalars/arrays round-trip in every mode.
- Move the allowedClasses documentation into the class docblock option list
  to match the convention used for every other config key.

---------

Co-authored-by: XananasX7 <xananasX7@users.noreply.github.com>
Co-authored-by: Mark Scherer <dereuromark@users.noreply.github.com>

5.4.0-RC1

Toggle 5.4.0-RC1's commit message
Merge branch '5.x' into 5.next

5.3.6

Toggle 5.3.6's commit message
Merge pull request #19320 from cakephp/next-branch-alias

Update branch alias for 5.next => 5.4

5.3.5

Toggle 5.3.5's commit message
Merge pull request #19320 from cakephp/next-branch-alias

Update branch alias for 5.next => 5.4

5.3.4

Toggle 5.3.4's commit message
Merge pull request #19320 from cakephp/next-branch-alias

Update branch alias for 5.next => 5.4