CVE-2025-48493

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs. Version 2.0.20 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

05 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-05 17:15

Updated : 2025-06-05 20:12


NVD link : CVE-2025-48493

Mitre link : CVE-2025-48493

CVE.ORG link : CVE-2025-48493


JSON object : View

Products Affected

No product.

CWE
CWE-532

Insertion of Sensitive Information into Log File