CVE-2024-55638
CRITICALDescription
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
Is your site exposed to CVE-2024-55638?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| drupal | drupal |
| drupal | drupal |
| drupal | drupal |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-55638? +
How severe is CVE-2024-55638? +
What products are affected by CVE-2024-55638? +
How do I check if I'm vulnerable to CVE-2024-55638? +
Related Vulnerabilities
An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determined Object Attributes, has been identified in the MXsecurity …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, …
Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are vulnerable to python class pollution vulnerability. …
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in …
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in …