CVE-2024-55638

Severity
9.8CRITICAL
EPSS
5.1%
top 10.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10

Description

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to an

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Packagistdrupal/core8.8.010.2.11+3
CVEListV5drupal/drupal_core7.07.102+2
Packagistdrupal/core-recommended8.8.010.2.11+2
NVDdrupal/drupal7.07.102+2
Packagistdrupal/drupal8.8.010.2.11+2

🔴Vulnerability Details

5
OSV
Drupal core contains a potential PHP Object Injection vulnerability2024-12-10
OSV
CVE-2024-55638: Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection2024-12-10
GHSA
Drupal core contains a potential PHP Object Injection vulnerability2024-12-10
CVEList
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-0082024-12-09
OSV
CVE-2024-55638: Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Remote Code Execution2024-11-20

📋Vendor Advisories

1
Drupal
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-0082024-11-20
CVE-2024-55638 (CRITICAL CVSS 9.8) | Deserialization of Untrusted Data v | cvebase.io