CVE-2025-48493

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Version 2.0.20 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yiiframework:yii2-redis:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-06-05 17:15

Updated : 2025-09-18 14:08


NVD link : CVE-2025-48493

Mitre link : CVE-2025-48493

CVE.ORG link : CVE-2025-48493


JSON object : View

Products Affected

yiiframework

  • yii2-redis
CWE
CWE-532

Insertion of Sensitive Information into Log File