Security Advisory

CVE-2017-6920

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-08-06 15:00:00
Last updated 2024-09-16 18:33:33
Assigner drupal
CVSS score not scored
State PUBLISHED

Description

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.