CVE-2017-6920
critical · 9.8Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
9.8
CVSS
20.5%
EPSS (exploit prob.)
97th
EPSS percentile
2018-08-06
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-19
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| drupal | drupal | >= 8.0.0, < 8.3.4 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/99211
- http://www.securitytracker.com/id/1038781
- https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiple
- http://www.securityfocus.com/bid/99211
- http://www.securitytracker.com/id/1038781
- https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiple
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-6920