Intel

AIKIDO-2024-10400

yiisoft/yii is vulnerable to Prototype Pollution

Prototype PollutionCVE-2021-20086 Published Nov 4, 2024

48

Medium Risk

This Affects:

phpyiisoft/yii
1.1.0 - 1.1.29
Fixed in 1.1.30
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to prototype pollution through code in the jquery.ba-bbq.js file. This vulnerability, identified as CVE-2021-20086, allows an attacker to modify the prototype of built-in objects in JavaScript. Although the issue was recognized, it was never addressed in yiisoft/yii, leaving applications using affected versions exposed to potential manipulation of object properties, which could lead to unexpected behavior or security vulnerabilities.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

yiisoft/yii is vulnerable to Prototype Pollution in versions 1.1.0 - 1.1.29.

How to fix this

Upgrade the yiisoft/yii library to the patch version.