Framework'ün açığı olan veri tabanı unserialize açığının önüne geçmeleri için aşağıya döküman paylaşıyorum.

AutoVM kullanan herkes aşağıdaki adımları uygulayabilir.

composer.json dosyasını aşağıdaki gibi

{
    "name": "yiisoft/yii2-app-basic",
    "description": "Yii 2 Basic Project Template",
    "keywords": ["yii2", "framework", "basic", "project template"],
    "homepage": "http://www.yiiframework.com/",
    "type": "project",
    "license": "BSD-3-Clause",
    "support": {
        "issues": "https://github.com/yiisoft/yii2/issues?state=open",
        "forum": "http://www.yiiframework.com/forum/",
        "wiki": "http://www.yiiframework.com/wiki/",
        "irc": "irc://irc.freenode.net/yii",
        "source": "https://github.com/yiisoft/yii2"
    },
    "minimum-stability": "stable",
    "require": {
        "php": ">=5.4.0",
        "yiisoft/yii2": "~2.0.40",
        "yiisoft/yii2-swiftmailer": "~2.0.0 || ~2.1.0",
        "sinergi/browser-detector": "dev-master",
        "kartik-v/yii2-grid": "^3.3@dev",
        "yiisoft/yii2-bootstrap": "~2.0.6",
        "rmrevin/yii2-fontawesome": "~3.5"
    },
    "require-dev": {
        "yiisoft/yii2-debug": "~2.1.0",
        "yiisoft/yii2-gii": "~2.1.0",
        "yiisoft/yii2-faker": "~2.0.0",
        "codeception/codeception": "^4.0",
        "codeception/verify": "~0.5.0 || ~1.1.0",
        "codeception/specify": "~0.4.6",
        "symfony/browser-kit": ">=2.7 <=4.2.4",
        "codeception/module-filesystem": "^1.0.0",
        "codeception/module-yii2": "^1.0.0",
        "codeception/module-asserts": "^1.0.0"
    },
    "config": {
        "process-timeout": 1800,
        "fxp-asset": {
            "enabled": false
        },
        "allow-plugins": {
            "yiisoft/yii2-composer": true
        }
    },
    "scripts": {
        "post-install-cmd": [
            "yii\\composer\\Installer::postInstall"
        ],
        "post-create-project-cmd": [
            "yii\\composer\\Installer::postCreateProject",
            "yii\\composer\\Installer::postInstall"
        ]
    },
    "extra": {
       "yii\\composer\\Installer::postCreateProject": {
                "setPermission": [
                    {
                        "runtime": "0777",
                        "web/assets": "0777",
                        "yii": "0755"
                    }
            ]
        },
        "yii\\composer\\Installer::postInstall": {
                "generateCookieValidationKey": [
                    "config/web.php"
                ]
        }
    },
    "repositories": [
        {
            "type": "composer",
            "url": "https://asset-packagist.org"
        }
    ]
}
gibi değiştirip var olan vendor klasörü, composer.phar dosyası, composer.lock dosyalarını sildikten sonra tekrar composer install yapmaları.

Composer işlemini gerçekleştiremeyenler için hazır vendor linkini aşağıya koyuyorum.

https://drive.google.com/file/d/13qJ...ew?usp=sharing

ana dizine atıp tar zxvf vendor.tar.gz ile unpack yapabilirsiniz.

bunu yaptıktan sonra sırası ile

modules-admin-assets-Asset.php
modules-site-assets-Asset.php

dosyalarını açıp

app\assets\FontAwesomeAsset
bulup
rmrevin\yii\fontawesome\CdnProAssetBundle
ile değiştiriniz.