CRITICAL KEV
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025
Published Apr 10, 2025 ·Due May 23, 2025
9.8
CRITICALCVSS 3.1
EPSS 87.76%
Description
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Affected products
-
Affected
- ≥ 2, < 2.0.52
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Yiiframework | Yii | unaffected | Affected
|
- < 2.0.52
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10502 Advisory
- https://github.com/advisories/GHSA-ggwg-cmwp-46r5 Advisory
- https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12 Patch
- https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52 Issue Tracking
- https://github.com/yiisoft/yii2/pull/20232 Patch
- https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2024-58136
- https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms technical-descriptionExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-58136 government-resourceUS Government Resource
- https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10502 | Advisory | |
| https://github.com/advisories/GHSA-ggwg-cmwp-46r5 | Advisory | |
| https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12 | Patch | |
| https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52 | Issue Tracking | |
| https://github.com/yiisoft/yii2/pull/20232 | Patch | |
| https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-58136 | ||
| https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms | technical-descriptionExploitThird Party Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-58136 | government-resourceUS Government Resource | |
| https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 10, 2025
Updated Oct 21, 2025
Reserved Apr 10, 2025
Link CVE-2024-58136
CISA Vulnrichment
Updated May 2, 2025
Red Hat
No data
ENISA EUVD
Assigner mitre
Published Apr 10, 2025
Updated Oct 21, 2025
Exploited since May 2, 2025
Link EUVD-2025-10502
GitHub
Link GHSA-GGWG-CMWP-46R5