CVE-2020-13673
EPSS 0.15%
描述
The Drupal core Media module allows embedding internal and external media in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed media. In some cases, this could lead to cross-site scripting. This advisory is not covered by [Drupal Steward](/steward). Also see [Entity Embed - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2021-028](https://www.drupal.org/sa-contrib-2021-028) which addresses a similar vulnerability for that module. *Updated 18:15 UTC to clarify text.*
如何修補 CVE-2020-13673
要修補 CVE-2020-13673,請將受影響套件升級到下列已修補版本。
- —升級至 8.9.19 或更新版本
- —升級至 1.2.0 或更新版本
CVE-2020-13673 正在被利用嗎?
低 — EPSS 為 0.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 8.0.0, < 8.9.19 | >= 9.1.0, < 9.1.13 | >= 9.2.0, < 9.2.6
- from 0, < 1.2.0