Metrics
Affected Vendors & Products
Mon, 24 Mar 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yiiframework
Yiiframework yii |
|
| CPEs | cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yiiframework
Yiiframework yii |
Mon, 24 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | yiisoft Yii2 SortableIterator.php getIterator deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-24T07:00:07.140Z
Updated: 2025-03-24T12:17:13.656Z
Reserved: 2025-03-23T09:36:26.587Z
Link: CVE-2025-2689
Updated: 2025-03-24T12:17:07.730Z
Status : Analyzed
Published: 2025-03-24T07:15:14.010
Modified: 2025-03-24T17:17:26.607
Link: CVE-2025-2689
No data.