Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
References
History

Mon, 16 Dec 2024 17:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

Tue, 10 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Dec 2024 23:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
Title Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007
Weaknesses CWE-915
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published: 2024-12-09T23:25:32.356Z

Updated: 2024-12-16T17:10:40.749Z

Reserved: 2024-12-09T23:07:41.397Z

Link: CVE-2024-55637

cve-icon Vulnrichment

Updated: 2024-12-10T21:20:45.554Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-10T00:15:22.650

Modified: 2024-12-16T18:15:11.673

Link: CVE-2024-55637

cve-icon Redhat

No data.