← Back to CVE List
Vulnerability Intelligence Report
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008

CVE-2024-55638

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.96%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-915 ↗CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

Affected Products & Versions

Vendor Product Affected Versions
Drupal Drupal Core 7.0 < 7.102 (affected), 8.0.0 < 10.2.11 (affected), 10.3.0 < 10.3.9 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.956%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDrupal.org · Vendor · USA
Reserved2024-12-09T23:07:41
Published2024-12-09T23:26:30
Patch Date2024-11-21
Last Updated2024-12-16T17:11:20

LINK COPIED TO CLIPBOARD