Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Description
Published to the GitHub Advisory Database
Jun 5, 2025
Reviewed
Jun 5, 2025
Published by the National Vulnerability Database
Jun 5, 2025
Last updated
Jun 6, 2025
Impact
On failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs.
References