Improper Protection of Alternate Path Affecting yiisoft/yii2 package, versions >=2.0.50, <2.0.52


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked
EPSS
0.07% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-YIISOFTYII2-9680255
  • published10 Apr 2025
  • disclosed10 Apr 2025
  • creditNicolas Bourras, Thomas Reynolds

Introduced: 10 Apr 2025

NewCVE-2024-58136  (opens in a new tab)
CWE-424  (opens in a new tab)

How to fix?

Upgrade yiisoft/yii2 to version 2.0.52 or higher.

Overview

yiisoft/yii2 is a Yii PHP Framework.

Affected versions of this package are vulnerable to Improper Protection of Alternate Path when defining a __class array key in the __set function of Component.php. An attacker can achieve code execution by manipulating the input to the behavior attachment process.

Note: This vulnerability was caused as an unintended side effect of the fix for the vulnerability described in CVE-2024-4990.

CVSS Base Scores

version 4.0
version 3.1