CVE-2024-58136: critical vulnerability in yiiframework Yii
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Yii 2 framework versions before 2.0.52 have a flaw that allows attackers to exploit how behaviors are attached using a __class array key, enabling unauthorized code execution. This is a regression from a previous fix and was actively exploited in the wild.
CWE-424 (Unrestricted Upload of File with Dangerous Type) relates to unsafe object instantiation via the __class parameter in behavior attachment. The vulnerability allows remote code execution when untrusted input is processed during behavior configuration, with no authentication required. Exploitation involves crafting malicious payloads in behavior definitions that instantiate arbitrary classes, a regression from CVE-2024-4990.
The full analysis of this CVE is available in Portuguese →