{"id":"CVE-2021-3689","aliases":["GHSA-hq3v-rg6f-6hx4"],"url":"https://o3.security/vulnerability/CVE-2021-3689","summary":"Use of Insufficiently Random Values in yiisoft/yii2-dev","details":"yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator","published":"2021-08-10T11:15:09.640Z","modified":"2026-08-07T17:02:22.793060Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.01902,"percentile":0.77845,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.43"}],"fix":{"url":"https://github.com/yiisoft/yii2/commit/13f27e4d920a05d53236139e8b07007acd046a46","label":"yiisoft/yii2@13f27e4"},"references":[{"type":"FIX","url":"https://github.com/yiisoft/yii2/commit/13f27e4d920a05d53236139e8b07007acd046a46"},{"type":"EVIDENCE","url":"https://huntr.dev/bounties/50aad1d4-eb00-4573-b8a4-dbe38e2c229f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:02:22.793060Z"}}