Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Drupal | Drupal | 8.0.0 (including) | 8.3.4 (excluding) |