CVE-2024-58136
Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 23 May 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 84.61% probability · 100th percentile
- CISA KEV
- Listed 2 May 2025 · due 23 May 2025
- Weakness
- CWE-424
- Affected
- yiiframework/yii
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52 ; https://nvd.nist.gov/vuln/detail/CVE-2024-58136
References
- https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12Patch
- https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52Issue Tracking
- https://github.com/yiisoft/yii2/pull/20232Patch
- https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709Issue Tracking
- https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52Vendor Advisory
- https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-58136US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.