CVE-2024-58136
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Yiiframework Yii Improper Protection of Alternate Path Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 85% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-424
מוצרים מושפעים
yiiframework: yii
קישורים
- https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52 Vendor Advisory
- https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12 Patch
- https://github.com/yiisoft/yii2/pull/20232 Patch
- https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rc… ExploitThird Party Advisory
- https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52 Issue Tracking
- https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709 Issue Tracking
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource