CVE-2020-13671
Drupal core Unrestricted Upload of File with Dangerous Type
8.8
HIGH
CVSS 3.1
⚠ KEVEPSS 4.3%
描述
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
如何修補 CVE-2020-13671
要修補 CVE-2020-13671,請將受影響套件升級到下列已修補版本。
- —升級至 7.74.0 或更新版本
- —升級至 8.8.11 或更新版本
- —升級至 9.0.8 或更新版本
- —升級至 7.74 或更新版本
CVE-2020-13671 正在被利用嗎?
是 — CVE-2020-13671 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(4)
- >= 7.0.0, < 7.74.0, >= 8.8.0, < 8.8.11, >= 8.9.0, < 8.9.9, >= 9.0.0, < 9.0.8
- >= 8.0.0, < 8.8.11 | >= 8.9.0, < 8.9.9 | >= 9.0.0, < 9.0.8
- >= 9.0.0, < 9.0.8
- >= 7.0.0, < 7.74
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H |