VDB
Sign up
HIGH8.1

GHSA-m2p5-fwp2-qcw2

Yii Framework Code Injection

Quick fix

GHSA-m2p5-fwp2-qcw2 — yiisoft/yii2-dev: upgrade to the fixed version with the command below.

composer require yiisoft/yii2-dev:^2.0.15

Details

Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2-dev
Introduced in: 2.0.0Fixed in: 2.0.15
Fixcomposer require yiisoft/yii2-dev:^2.0.15
Packagist/yiisoft/yii2-elasticsearch
Introduced in: 0Fixed in: 2.0.5
Fixcomposer require yiisoft/yii2-elasticsearch:^2.0.5

References