Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3453 | Drupal core contains a potential PHP Object Injection vulnerability |
Github GHSA |
GHSA-938f-5r4f-h65v | Drupal core contains a potential PHP Object Injection vulnerability |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-core-2024-006 |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 02 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal drupal |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Drupal
Drupal drupal |
Mon, 16 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability. |
Tue, 10 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 09 Dec 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. | |
| Title | Drupal core - Less critical - Gadget chain - SA-CORE-2024-006 | |
| Weaknesses | CWE-915 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2024-12-16T17:09:36.830Z
Reserved: 2024-12-09T23:07:41.397Z
Link: CVE-2024-55636
Updated: 2024-12-10T21:21:34.654Z
Status : Analyzed
Published: 2024-12-10T00:15:22.540
Modified: 2025-06-02T16:23:09.030
Link: CVE-2024-55636
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA