VDB
Sign up
MEDIUM6.3

GHSA-88m2-j94x-v4fx

yiisoft Yii2 Deserialization of Untrusted Data

Details

A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2-dev
Introduced in: 0

No fixed version published yet for yiisoft/yii2-dev (composer). Pin to a known-safe version or switch to an alternative.

References