CVE CVE

CVE-2024-58136

CISA Known Exploited Vulnerability (KEV)

Yiiframework Yii Improper Protection of Alternate Path Vulnerability

May 2, 2025

May 23, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

Weakness Enumeration

CWE-ID CWE Name

CWE-424
Improper Protection of Alternate Path

Known Affected Software Configurations


cpe:2.3:a:yiiframework:yii:2.0.48:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.44:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.45:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.46:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.47:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.39.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.39.2:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.39.3:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.39:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.40:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.41.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.41:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.42.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.42:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.43:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.38:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.37:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.36:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.35:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.34:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.33:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.32:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.31:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.30:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.29:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.28:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.27:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.26:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.25:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.24:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.23:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.22:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.21:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.20:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.19:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.18:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.17:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.16.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.16:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.15.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.15:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.14.2:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.14.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.14:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.13.3:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.13.2:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.13.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.13:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.12.2:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.12.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.12:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.11.2:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.11.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.11:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.10:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.9:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.8:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.7:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.6:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.5:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.4:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.3:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.2:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.0:rc:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.0:beta:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.0:alpha:*:*:*:*:*:*

cpe:2.3:a:yiiframework:yii:2.0.0:-:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v2

Not defined