CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-58136

CVSS 9.0v3.1pub. 2025-04-10upd. 2025-11-05

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

🤖 AI Analysis
How it works

The Yii 2 framework allows dynamic attachment of behaviors to components through array configuration containing a special __class key. Due to a regression introduced after the CVE-2024-4990 fix, the configuration processing mechanism again contains a flaw that allows an attacker to substitute a malicious class. An unauthenticated remote attacker can remotely deliver crafted input, leading to uncontrolled object instantiation and server-side code execution.

Impact

An attacker can gain full control over the application server — achieve remote code execution (RCE), access sensitive data, and permanently compromise system integrity and availability.

Mitigation & patch

Yii 2 must be immediately updated to version 2.0.52 or later. The patch is available in the project repository (commit 40fe496) and described in the official vendor advisory at https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52

Who is affected

Yii 2 versions before 2.0.52 (Yiiframework Yii)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Yiiframework Yii

    APP
    Yiiframework
    < 2.0.52

CISA KEV — detailsi

Vendori
Yiiframework
Producti
Yii
Added to KEVi
May 2, 2025
Remediation deadline (US Federal)i
May 23, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 23 maja 2025
CWE
References

Related vulnerabilities

CVE-2024-4990CRITICAL9.1PL ✓same product

Yii2: Instantiacja dowolnych klas przez metodę __set() w klasie Component

CVE-2015-5467CRITICAL9.8PL ✓same product

Path Traversal w Yii2 umożliwiający wykonanie dowolnego pliku PHP

CVE-2023-26750CRITICAL9.8PL ✓same product

SQL injection w Yii 2 Framework umożliwiający zdalne wykonanie kodu

CVE-2018-8073CRITICAL9.8PL ✓same product

Zdalne wykonanie kodu LUA w Yii Framework przez rozszerzenie Redis

CVE-2018-7269CRITICAL9.8PL ✓same product

SQL Injection w Yii 2.x — podatna funkcja findByCondition()