Описание
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
drupal8 | itp | package |
Примечания
https://www.drupal.org/SA-CORE-2017-003
EPSS
Процентиль: 98%
0.67036
Средний
Связанные уязвимости
CVSS3: 9.8
nvd
около 7 лет назад
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
EPSS
Процентиль: 98%
0.67036
Средний