—
DRUPAL-CONTRIB-2018-022
Details
This module enables you to monitor and manage any number of remote Drupal sites and aggregate useful information for administrators in a central dashboard.
The modules (DRD and DRD Agent) encrypt the data which is exchanged between them but in order to do so, they use the PHP serialize/unserialize functions instead of the json\_encode/json\_decode combination. As the unserialize function is called on unauthenticated content, this introduces a PHP object injection vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/drd_agent
Introduced in:
0Fixed in: 3.7.0Upgrade drupal/drd_agent to 3.7.0 or newer (ecosystem packagist:https://packages.drupal.org/8).