First published: Thu Apr 10 2025(Updated: )
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yii Framework | <2.0.52 | |
composer/yiisoft/yii2 | <2.0.52 | 2.0.52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-58136 has been classified as a critical vulnerability due to its exploitation in the wild.
To fix CVE-2024-58136, you should upgrade Yii 2 to version 2.0.52 or later.
CVE-2024-58136 affects Yii 2 versions prior to 2.0.52.
CVE-2024-58136 is a vulnerability related to the mishandling of behavior attachments in the Yii framework.
CVE-2024-58136 was reportedly exploited in the wild between February and April 2025.