From 5c3a1312edcb3992bc8f05872a8fccb796066c8b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 6 Jun 2025 16:01:39 +0000 Subject: [PATCH] Publish GHSA-g3p6-82vc-43jh --- .../2025/06/GHSA-g3p6-82vc-43jh/GHSA-g3p6-82vc-43jh.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2025/06/GHSA-g3p6-82vc-43jh/GHSA-g3p6-82vc-43jh.json b/advisories/github-reviewed/2025/06/GHSA-g3p6-82vc-43jh/GHSA-g3p6-82vc-43jh.json index 69d61b9b76c..acd65fa326b 100644 --- a/advisories/github-reviewed/2025/06/GHSA-g3p6-82vc-43jh/GHSA-g3p6-82vc-43jh.json +++ b/advisories/github-reviewed/2025/06/GHSA-g3p6-82vc-43jh/GHSA-g3p6-82vc-43jh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g3p6-82vc-43jh", - "modified": "2025-06-05T20:14:46Z", + "modified": "2025-06-06T15:59:53Z", "published": "2025-06-05T16:53:23Z", "aliases": [ "CVE-2025-48493" ], - "summary": "Yii 2 Redis may expose AUTH paramters in logs in case of connection failure", + "summary": "Yii 2 Redis may expose AUTH parameters in logs in case of connection failure", "details": "### Impact\n\nOn failing connection extension writes commands sequence to logs. AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to logs.", "severity": [ {