CRITICAL9.8
GHSA-4hx3-m8w5-g5qh
yii2-redis Potential Remote code execution
Quick fix
GHSA-4hx3-m8w5-g5qh — yiisoft/yii2-redis: upgrade to the fixed version with the command below.
composer require yiisoft/yii2-redis:^2.0.8Details
Potential remote code execution in LUA context of the redis server via methods `yii\redis\ActiveRecord::findOne()` and `yii\redis\ActiveRecord::findAll()` in yiisoft/yii2-redis. Attackers could probably manipulate data on the redis server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/yiisoft/yii2-redis
Introduced in:
0Fixed in: 2.0.8Fix
composer require yiisoft/yii2-redis:^2.0.8References
- https://nvd.nist.gov/vuln/detail/CVE-2018-8073[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/yiisoft/yii2-redis/CVE-2018-8073.yaml[WEB]
- https://github.com/yiisoft/yii2-redis[PACKAGE]
- https://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes[WEB]
- http://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes[WEB]