PT-2025-23939 · Yii · Yii 2 Redis Extension

Samdark

·

Publicado

2025-06-05

·

Atualizado

2025-06-05

·

CVE-2025-48493

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Yii 2 Redis extension versions prior to 2.0.20
Description The issue concerns the logging of commands when a connection fails in the Yii 2 Redis extension. Specifically, prior to version 2.0.20, AUTH parameters are written in plain text, exposing the username and password. This could be problematic if an attacker gains access to the logs.
Recommendations For versions prior to 2.0.20, update to version 2.0.20 to resolve the issue. As a temporary workaround, consider restricting access to the logs to minimize the risk of exploitation.

Exploit

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-09066
CVE-2025-48493
GHSA-G3P6-82VC-43JH

Produtos afetados

Yii 2 Redis Extension