Vulnerability Intelligence Report
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007
CVE-2024-55637
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.80%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-915 ↗CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Drupal | Drupal Core | 8.0.0 < 10.2.11 (affected), 10.3.0 < 10.3.9 (affected), 11.0.0 < 11.0.8 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.803%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Drupal.org · Vendor · USA |
| Reserved | 2024-12-09T23:07:41 |
| Published | 2024-12-09T23:25:32 |
| Patch Date | 2024-11-21 |
| Last Updated | 2024-12-16T17:10:40 |
Community Chatter & Buzz