yiisoft/yii2-redis
Yii 2 Redis extension.
Activity
- Latest release
- 4mo ago
- Total releases
- 27
- Cadence
- ~4 months
- Last 12 months
- 3
Reach
- Stars
- 449
Details
- License
- BSD-3-Clause
- First release
- Nov 30, 2013
| Version | Released | |
|---|---|---|
2.1.2
patch
|
2.1.2
patch
Dependencies (2)
Changelog
Compare changes
|
|
2.1.1
patch
| ||
2.1.0
minor
| ||
2.0.20
patch
| ||
2.0.19
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.18
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.17
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.16
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.15
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.14
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.13
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.12
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.11
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.10
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.9
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.8
patch
1 CVE
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev | ||
2.0.7
patch
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.6
patch
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.5
patch
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.4
patch
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.3
patch
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.2
patch
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.1
patch
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.0
initial
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.0-rc
pre
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.0-beta
pre
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev | ||
2.0.0-alpha
pre
2 CVEs
CVE-2025-48493
GHSA-g3p6-82vc-43jh
Jun 05, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Medium
Network
Low
High
None
ImpactOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
+ 11 more Show less
2.0.17
2.0.18
2.0.19
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jun 06, 2025 · Source: OSV.dev
CVE-2018-8073
GHSA-4hx3-m8w5-g5qh
May 14, 2022
yii2-redis Potential Remote code execution
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Potential remote code execution in LUA context of the redis server via methods Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
Fixed in
2.0.8
References
Updated Apr 24, 2024 · Source: OSV.dev |