A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 24 Mar 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Yiiframework
Yiiframework yii
CPEs cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*
Vendors & Products Yiiframework
Yiiframework yii

Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title yiisoft Yii2 MockClass.php generate deserialization
Weaknesses CWE-20
CWE-502
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-24T12:14:34.960Z

Reserved: 2025-03-23T09:36:29.048Z

Link: CVE-2025-2690

cve-icon Vulnrichment

Updated: 2025-03-24T12:14:29.795Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-24T08:15:12.793

Modified: 2025-03-24T17:15:40.917

Link: CVE-2025-2690

cve-icon Redhat

No data.