CVE Database
/

CVE-2024-55638

Back to search

CVE-2024-55638

Published: Dec 9, 2024

Modified: Dec 16, 2024

PUBLISHED

Description

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

VendorProductVersions

Drupal

Drupal Core

affected
7.0 - < 7.102
affected
8.0.0 - < 10.2.11
affected
10.3.0 - < 10.3.9

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now