CVE-2017-6920: Code Injection
Published Jun 21, 2017
·Updated
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
Affected Software
5 affected componentsFixes available
composer/drupal/core>=8.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.3.4
composer/drupal/drupal>=8.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.3.4
composer/drupal/drupal>=8.0<8.3.4
8.3.4
composer/drupal/core>=8.0<8.3.4
8.3.4
Drupal Drupal>=8.0.0<8.3.4
Remediation
Event History
Jun 21, 2017
Advisory Published
06:13 PM
Aug 6, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6920?
CVE-2017-6920 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2017-6920?
To fix CVE-2017-6920, upgrade Drupal core and Drupal to version 8.3.4 or later.
3
Which versions of Drupal are affected by CVE-2017-6920?
CVE-2017-6920 affects Drupal core versions prior to 8.3.4 including 8.0.x, 8.1.x, and 8.2.x.
4
What type of vulnerability is CVE-2017-6920?
CVE-2017-6920 is a remote code execution vulnerability due to unsafe object handling by the PECL YAML parser.
5
Can CVE-2017-6920 be exploited remotely?
Yes, CVE-2017-6920 can be exploited remotely, allowing attackers to execute arbitrary code on the server.