CVE-2024-55636

Severity
9.8CRITICAL
EPSS
8.8%
top 7.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10

Description

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Packagistdrupal/core8.0.010.2.11+3
CVEListV5drupal/drupal_core8.0.010.2.11+2
Packagistdrupal/core-recommended8.8.010.2.11+2
NVDdrupal/drupal8.0.010.2.11+2
Packagistdrupal/drupal8.8.010.2.11+2

🔴Vulnerability Details

5
OSV
Drupal core contains a potential PHP Object Injection vulnerability2024-12-10
GHSA
Drupal core contains a potential PHP Object Injection vulnerability2024-12-10
OSV
CVE-2024-55636: Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection2024-12-10
CVEList
Drupal core - Less critical - Gadget chain - SA-CORE-2024-0062024-12-09
OSV
CVE-2024-55636: Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Artbitrary File Deletion2024-11-20

📋Vendor Advisories

1
Drupal
Drupal core - Less critical - Gadget chain - SA-CORE-2024-0062024-11-20
CVE-2024-55636 (CRITICAL CVSS 9.8) | Deserialization of Untrusted Data v | cvebase.io