漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Drupal core - Less critical - Gadget chain - SA-CORE-2024-006
Vulnerability Description
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
CVSS Information
N/A
Vulnerability Type
CWE-915
Vulnerability Title
Drupal core 安全漏洞
Vulnerability Description
Drupal core是Drupal社区的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal core 8.0.0版本至10.2.11之前版本、10.3.0版本至10.3.9之前版本和11.0.0版本至11.0.8之前版本存在安全漏洞,该漏洞源于不受信任数据的反序列化,允许对象注入。
CVSS Information
N/A
Vulnerability Type
N/A