Critical severity9.8NVD Advisory· Published Aug 6, 2018· Updated Jun 17, 2026
CVE-2017-6920
CVE-2017-6920
Description
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
drupal/corePackagist | >= 8.0, < 8.3.4 | 8.3.4 |
drupal/drupalPackagist | >= 8.0, < 8.3.4 | 8.3.4 |
Affected products
3- ghsa-coords2 versions
>= 8.0, < 8.3.4+ 1 more
- (no CPE)range: >= 8.0, < 8.3.4
- (no CPE)range: >= 8.0, < 8.3.4
- Range: 8 prior to 8.3.4
Patches
Vulnerability mechanics
References
8- www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiplenvdPatchVendor AdvisoryWEB
- www.securityfocus.com/bid/99211nvdThird Party AdvisoryVDB EntryWEB
- www.securitytracker.com/id/1038781nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-9c24-g32g-35rjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-6920ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2017-6920.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2017-6920.yamlghsaWEB
- www.drupal.org/SA-CORE-2017-003ghsaWEB
News mentions
0No linked articles in our index yet.