ZeroHour

CVE-2017-6920

CVSS 3.0
9.8 critical
EPSS
20%p97
Published
()
Modified
Description

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.

Vendors
drupal
Products
drupal
Ecosystems
Drupal
Weakness
CWE-19
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news