CVE Database
/

CVE-2025-48493

Back to search

CVE-2025-48493

Published: Jun 5, 2025

Modified: Jun 9, 2025

PUBLISHED

Description

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Version 2.0.20 fixes the issue.

VendorProductVersions

yiisoft

yii2-redis

affected
< 2.0.20

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now