First published: Mon Mar 24 2025(Updated: )
A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Yii Framework 2 | <=2.0.45 | |
Yii Framework | >=2.0.0<=2.0.45 | |
composer/yiisoft/yii2-dev | <=2.0.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2689 is classified as a critical vulnerability.
CVE-2025-2689 affects versions of yiisoft Yii2 up to 2.0.45.
To fix CVE-2025-2689, update yiisoft Yii2 to the latest version beyond 2.0.45.
CVE-2025-2689 is a deserialization vulnerability that can be exploited remotely.
The vulnerability in CVE-2025-2689 is located in the getIterator function of the file symfony\finder\Iterator\SortableIterator.php.