In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerabilities in an interactive lesson.
Start learningUpgrade drupal/core
to version 10.2.11, 10.3.9, 11.0.8 or higher.
drupal/core is an an open source content management platform powering millions of websites and applications.
Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes through the deserialization process. An attacker can execute arbitrary code or manipulate the application state.
Notes:
All versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. Drupal 8 and Drupal 9 have both reached end-of-life. Drupal 7 is not affected.
This is only exploitable if a separate vulnerability is present to allow an attacker to pass unsafe input to unserialize()
.