A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 24 Mar 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Yiiframework
Yiiframework yii
CPEs cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*
Vendors & Products Yiiframework
Yiiframework yii

Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Title yiisoft Yii2 SortableIterator.php getIterator deserialization
Weaknesses CWE-20
CWE-502
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-24T07:00:07.140Z

Updated: 2025-03-24T12:17:13.656Z

Reserved: 2025-03-23T09:36:26.587Z

Link: CVE-2025-2689

cve-icon Vulnrichment

Updated: 2025-03-24T12:17:07.730Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-24T07:15:14.010

Modified: 2025-03-24T17:17:26.607

Link: CVE-2025-2689

cve-icon Redhat

No data.