GHSA-4hx3-m8w5-g5qh
Dashboard / Vulnerabilities / GHSA-4hx3-m8w5-g5qh
Summary: yii2-redis Potential Remote code execution
Details: Potential remote code execution in LUA context of the redis server via methods `yii\redis\ActiveRecord::findOne()` and `yii\redis\ActiveRecord::findAll()` in yiisoft/yii2-redis. Attackers could probably manipulate data on the redis server.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-8073, https://github.com/FriendsOfPHP/security-advisories/blob/master/yiisoft/yii2-redis/CVE-2018-8073.yaml, https://github.com/yiisoft/yii2-redis, https://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes, http://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes
Affected packages
Package
Name: yiisoft/yii2-redis
Purl: pkg:composer/yiisoft/yii2-redis
Affected ranges
Type: ECOSYSTEM
Events:
