cve/2021/CVE-2021-3689.md

18 lines
666 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-3689](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3689)
![](https://img.shields.io/static/v1?label=Product&message=yiisoft%2Fyii2&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%3D%202.0.42.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-1241%20Use%20of%20Predictable%20Algorithm%20in%20Random%20Number%20Generator&color=brighgreen)
### Description
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
### POC
#### Reference
- https://huntr.dev/bounties/50aad1d4-eb00-4573-b8a4-dbe38e2c229f
#### Github
No PoCs found on GitHub currently.