CVE-2016-3171: Session data truncation can lead to unserialization of user provided data
(updated )
Drupal might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
References
Detect and mitigate CVE-2016-3171 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →