NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1708 most downloaded on Packagist
Redis Cache, Session and ActiveRecord for the Yii framework
Last release 5 months ago
07 May 2026
Release timing varies
gaps range from 2 months to 2.4 years
Nearly every release is documented
notes for 24 of 24 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
27 releases · first in 2013
Revert custom retry in PredisConnection after update predis package by @s1lver in #294
Full Changelog: 2.1.1...2.1.2
PredisConnection after update predis package (@s1lver)Dropped PHP 7.3 support to align with Yii2 minimum PHP version by @s1lver in #281
README.md and internals.md documentation; update scripts in composer.json for improved testing and code style checks. by @terabytesoftw in #288composer.json. by @terabytesoftw in #290fwrite() supplied resource is not a valid stream, bump version predis/predis to 3.4 by @s1lver in #292composer.json, and update CHANGELOG.md. by @terabytesoftw in #293Full Changelog: 2.1.0...2.1.1
One column per quarter.
parseResponse() when fread() returns empty string on broken socket (@dkostik)fwrite() supplied resource is not a valid stream (@s1lver)predis/predis to 3.4 (@s1lver)composer.json, and update CHANGELOG.md (@terabytesoftw)Fix #278: Prevent null parameter on SocketException to avoid PHP 8.4 implicity nullable types deprecation (HenryVolkmer)
null parameter on SocketException to avoid PHP 8.4 implicity nullable types deprecation (HenryVolkmer)yii\redis\Cache::$forceClusterMode to false (antonshevelev)yii\redis\ConnectionInterface in yii\redis\Connection (antonshevelev)Bug CVE-2025-48493: Prevent logging AUTH parameters when YII_DEBUG is off (samdark)
AUTH parameters when YII_DEBUG is off (samdark)mb_strlen to avoid PHP 8.4 implicity nullable types deprecation (tehmaestro)Enh #264: Improve performance of mget() for big list of keys (alx-xc, rob006)
mget() for big list of keys (alx-xc, rob006)Enh #249 Added support to set the redis scheme to tls. Add to configuration: 'scheme' => 'tls' (tychovbh)
'scheme' => 'tls' (tychovbh)Cache::getValue() now returns false in case of missing key (rhertogh)Enh #176: Fix reconnect logic bug, add protected function sendRawCommand() (ilyaplot)
protected function sendRawCommand() (ilyaplot)Enh #223: Add Connection::$username for using username for authentication (samdark, rvkulikov)
Connection::$username for using username for authentication (samdark, rvkulikov)Enh #227: Added support for adjusting PHP context options and parameters. This allows e.g. supporting self-signed certificates (akselikap)
Mar 20, 2018
Today we are releasing several versions for Yii 2.0.x and official extensions to fix a security issue.
The problem addressed in these patches exists in ActiveRecord shortcut methods findOne() and findAll() , which may allow SQL injection if input is not prepared properly. We consider this as a security issue in Yii because the documentation for these methods did not contain an explicit warning that there are cases when passing unfiltered user input might be dangerous. Thanks to analitic1983 for making us aware of the issue.
The nature of this issue does not solely exists in the Yii Framework but depends on how an application uses Yii. We have changed Yii to be more robust against the worst impact of the problem (SQL injection), but applications may still be vulnerable and changes to application code are necessary in some cases. As a safety measure, findOne() and findAll() are now limited to filter on columns that are AR properties only. In the following we will explain the problem in more detail and show which application code is affected and what needs to be adjusted on upgrade.
For discussion on this issue, there is a forum topic .
Not Affected Code
Affected Code
yii\db\ActiveRecord::findOne() and yii\db\ActiveRecord::findAll() in yiisoft/yii2 referenced as CVE-2018-7269 . Methods allow SQL injection if input is not prepared properly. Attackers could probably execute arbitrary SQL queries or circumvent access checking methods applied on query level.
yii\redis\ActiveRecord::findOne() and yii\redis\ActiveRecord::findAll() in yiisoft/yii2-redis referenced as CVE-2018-8073 . Methods allow remote code execution in redis servers lua script environment. Attackers could probably manipulate data on the redis server.
yii\elasticsearch\ActiveRecord::findOne() and yii\elasticsearch\ActiveRecord::findAll() in yiisoft/yii2-elasticsearch referenced as CVE-2018-8074 . Methods may allow injecting different search condition than desired or cause an error response from the elasticsearch server.
This vulnerability affects all releases of the 2.0.x branch. It is fixed in Yii 2.0.15. For versions below 2.0.15, we have released two patch versions, 2.0.13.2 and 2.0.12.1, which apply the fix to 2.0.13.1 and 2.0.12 respectively. Users of 2.0.14, can upgrade to 2.0.15, there are no other changes made in this release.
The methods findOne() and findAll() accept a single argument, which can be scalar or array. If the calling code ensures that a scalar is passed or if client inputs cannot modify the array's structure, your application is not affected by this issue. The following code examples are not affected by this issue (examples shown for findOne() are valid also for findAll() ):
// yii\web\Controller ensures that $id is scalar public function actionView ($id) { $model = Post::findOne($id); // ... }
// casting to (int) or (string) ensures no array can be injected (an exception will be thrown so this is not a good practise) $model = Post::findOne((int) Yii::$app->request->get( 'id' ));
// explicitly specifying the colum to search, passing a scalar or array here will always result in finding a single record $model = Post::findOne([ 'id' => Yii::$app->request->get( 'id' )]);
The following code however is vulnerable , an attacker could inject an array with an arbitrary condition and even exploit SQL injection:
$model = Post::findOne(Yii::$app->request->get( 'id' ));
For the above example, the SQL injection part is fixed with the patches provided in this release, but an attacker may still be able to search records by different condition than a primary key search and violate your application business logic. So passing user input directly like this can cause problems and should be avoided.
If you are using Yii 2.0.14:
composer require "yiisoft/yii2" : "~2.0.15.0"
If you are using Yii 2.0.13:
composer require "yiisoft/yii2" : "~2.0.13.2"
If you are using Yii 2.0.12:
composer require "yiisoft/yii2" : "~2.0.12.1"
If you are using yii2-redis extension:
composer require "yiisoft/yii2-redis" : "~2.0.8"
If you are using yii2-elasticsearch extension:
composer require "yiisoft/yii2-elasticsearch" : "~2.0.5"
Update: We have since released further patches to lower the impact of the BC break introduced by the security fix, so you get versions 2.0.15.1, 2.0.13.3 and 2.0.12.2 from the above.
Upgrading Yii addresses the SQL injection but doesn't make findOne() and findAll() safe in general. Check all usages of findOne() and findAll() in your application. Also note, that where() and filterWhere() never escape column names, so if you need to pass a variable as a column name, make sure it is safe.
Security lessons Yii learned thanks to GitHub Secure Open Source Fund
Yii 2.0.55
Yii2 Redis 2.1.1
Yii2 Redis 2.1.2
Yii 1.1.33 is released and security support extended
2.0.12
2.0.13
elasticsearch
redis
release
security
Yii 2.0
Bug #215: Fix Connection::isActive() returns false when the connection is active (cornernote)
Connection::isActive() returns false when the connection is active (cornernote)yii\web\Session (rhertogh)Enh #210: Add Redis 5.0 stream commands. Read more at streams intro (sartor)
Bug #182: Better handle cache/flush-all command when cache component is using shared database (rob006)
cache/flush-all command when cache component is using shared database (rob006)Instance::ensure() to initialize Session::$redis (rob006)$timeout is used in Mutex::acquire() (rob006)Enh #66, #134, #135, #136, #142, #143, #147: Support Redis in cluster mode (hofrob)
Enh #188: Added option to wait between connection retry (marty-macfly, rob006)
Bug #166: zrangebyscore without scores does not work (razonyang)
>, <, >= and <= conditions support in ActiveQuery (nailfor, zacksleo)Bug: (CVE-2018-8073): Fix possible remote code execution when improperly filtered user input is passed to ActiveRecord::findOne() and ::findAll() (ceb…
ActiveRecord::findOne() and ::findAll() (cebe)Bug #114: Fixed ActiveQuery not between and not conditions which where not working correctly (cebe, ak1987)
not between and not conditions which where not working correctly (cebe, ak1987)yii\redis\SocketException for these (cebe)Bug #44: Remove quotes from numeric parts of composite key to avoid problem with different hashes for the same record (uniserpl)
yii\redis\ActiveRecord::deleteAll() with condition (samdark)Mutex that implements a Redis based mutex (turboezh, sergeymakinen)Connection::$database to null to avoid sending a SELECT command after connection (cebe)\yii\db\QueryInterface::emulateExecution() (samdark)@method documentation for redis commands (cebe)Bug #22: Fixed string escaping issue in LuaScriptBuilder (vistart)
Connection::$socketClientFlags property for connection flags to be passed to stream_socket_client() (hugh-lee)BLPOP command to $redisCommands (samdark)GEO* commands to $redisCommands (leadermt)Enh #8: Auto increment value was not updated when a primary key was explicitly set (cebe, andruha)
- no changes in this release.
Bug #6547: Fixed redis connection to deal with large data in combination with mget() (pyurin)
mget() (pyurin)Bug #4745: value of simple string returns was ignored by redis client and true is returned instead, now only OK will result in a true while all other
true is returned instead, now only OK will result in a true while all other values are returned as is (cebe)- no changes in this release.
Bug #1311: Fixed storage and finding of null and boolean values (samdark, cebe)
null and boolean values (samdark, cebe)unlinkAll()-method to active record to remove all records of a model relation (NmDimas, samdark, cebe)init event to ActiveQuery classes (qiangxue)Bug #1993: afterFind event in AR is now called after relations have been populated (cebe, creocoder)
afterSave() so information about changed attributes is available in afterSave-event (cebe)ActiveRecord::create() to populateRecord() and changed signature. This method will not call instantiate() anymore (cebe)ActiveRelation class and moved the functionality to ActiveQuery.
All relational queries are now directly served by ActiveQuery allowing to use
custom scopes in relations (cebe)- Initial release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →