PT-2025-23939 · Yii · Yii 2 Redis Extension

Samdark

·

Published

2025-06-05

·

Updated

2025-06-05

·

CVE-2025-48493

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Yii 2 Redis extension versions prior to 2.0.20
Description The issue concerns the logging of commands when a connection fails in the Yii 2 Redis extension. Specifically, prior to version 2.0.20, AUTH parameters are written in plain text, exposing the username and password. This could be problematic if an attacker gains access to the logs.
Recommendations For versions prior to 2.0.20, update to version 2.0.20 to resolve the issue. As a temporary workaround, consider restricting access to the logs to minimize the risk of exploitation.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2025-09066
CVE-2025-48493
GHSA-G3P6-82VC-43JH

Affected Products

Yii 2 Redis Extension