yiisoft/yii is vulnerable to Prototype Pollution
48
Medium Risk
Affected versions of this package are vulnerable to prototype pollution through code in the jquery.ba-bbq.js file. This vulnerability, identified as CVE-2021-20086, allows an attacker to modify the prototype of built-in objects in JavaScript. Although the issue was recognized, it was never addressed in yiisoft/yii, leaving applications using affected versions exposed to potential manipulation of object properties, which could lead to unexpected behavior or security vulnerabilities.
You are affected if you are using a version that falls within the vulnerable range.
yiisoft/yii is vulnerable to Prototype Pollution in versions 1.1.0 - 1.1.29.
Upgrade the yiisoft/yii library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant