RULE(RULE ID:335414)

Rule General Information
Release Date: 2021-12-20
Rule Name: Drupal core 8 PECL YAML Parser Remote Code Execution Vulnerability (CVE-2017-6920)
Severity:
CVE ID:
Rule Protection Details
Description: Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:99211
SecurityTrackerID:1038781
https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiple
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiple