CVE-2024-55637

Severity
9.8CRITICAL
EPSS
7.6%
top 8.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10

Description

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due t

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Packagistdrupal/core8.8.010.2.11+3
CVEListV5drupal/drupal_core8.0.010.2.11+2
Packagistdrupal/core-recommended8.8.010.2.11+2
NVDdrupal/drupal8.0.010.2.11+2
Packagistdrupal/drupal8.8.010.2.11+2

🔴Vulnerability Details

5
OSV
Drupal core contains a potential PHP Object Injection vulnerability2024-12-10
OSV
CVE-2024-55637: Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection2024-12-10
GHSA
Drupal core contains a potential PHP Object Injection vulnerability2024-12-10
CVEList
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-0072024-12-09
OSV
CVE-2024-55637: Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Remote Code Execution2024-11-20

📋Vendor Advisories

1
Drupal
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-0072024-11-20
CVE-2024-55637 (CRITICAL CVSS 9.8) | Deserialization of Untrusted Data v | cvebase.io