← back
CVE-2017-6920

CVE-2017-6920

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 20%
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
Affected products
Drupal.org · Drupal Core