CVE-2018-8074: Code Injection
Possibility of manipulated condition when unfiltered input is passed to yii\elasticsearch\ActiveRecord::findOne() and ::findAll()
Other sources
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/yiisoft/yii2-elasticsearchto a version that resolves this vulnerability.Fixed in 2.0.5 - Upgrade
Upgrade
composer/yiisoft/yii2-devto a version that resolves this vulnerability.Fixed in 2.0.15
Event History
Frequently Asked Questions
What is CVE-2018-8074?
CVE-2018-8074 is a vulnerability in Yii 2.x before 2.0.15 that allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.
How does CVE-2018-8074 affect Yii?
CVE-2018-8074 affects Yii 2.x before version 2.0.15, specifically the yii2-elasticsearch package.
What is the severity of CVE-2018-8074?
CVE-2018-8074 has a severity rating of 8.1 (High).
How can I fix CVE-2018-8074?
To fix CVE-2018-8074, you should update to Yii version 2.0.15 or apply the necessary security fixes.
Are there any references for CVE-2018-8074?
Yes, you can find more information about CVE-2018-8074 at the following references: [1] [2] [3].