← Back to CVE List
Vulnerability Intelligence Report
Drupal core - Less critical - Gadget chain - SA-CORE-2024-006

CVE-2024-55636

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.90%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-915 ↗CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

Affected Products & Versions

Vendor Product Affected Versions
Drupal Drupal Core 8.0.0 < 10.2.11 (affected), 10.3.0 < 10.3.9 (affected), 11.0.0 < 11.0.8 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.904%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDrupal.org · Vendor · USA
Reserved2024-12-09T23:07:41
Published2024-12-09T23:24:27
Patch Date2024-11-21
Last Updated2024-12-16T17:09:36

LINK COPIED TO CLIPBOARD