CVE-2019-6340
Drupal Core Remote Code Execution Vulnerability
描述
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)
如何修補 CVE-2019-6340
要修補 CVE-2019-6340,請將受影響套件升級到下列已修補版本。
- —升級至 8.5.11 或更新版本
- —升級至 8.6.10 或更新版本
- —升級至 7.62.0 或更新版本
CVE-2019-6340 正在被利用嗎?
是 — CVE-2019-6340 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(3)
- >= 8.0.0, < 8.5.11 | >= 8.6.0, < 8.6.10
- >= 8.6.0, < 8.6.10
- >= 7.0.0, < 7.62.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H |