CVE-2018-7600: Drupal Core Remote Code Execution Vulnerability
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
Other sources
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/drupal7to a version that resolves this vulnerability.Fixed in 7.58-1Fixed in 7.52-2+deb9u3Fixed in 7.32-1+deb8u11 - Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 8.5.1 - Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 8.4.6 - Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 8.3.9 - Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 7.58 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 8.5.1 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 8.4.6 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 8.3.9 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 7.58 - Upgrade
Upgrade
Drupal Coreto a version that resolves this vulnerability.Fixed in 7.58 - Upgrade
Upgrade
Drupal Coreto a version that resolves this vulnerability.Fixed in 8.3.9 - Upgrade
Upgrade
Drupal Coreto a version that resolves this vulnerability.Fixed in 8.4.6 - Upgrade
Upgrade
Drupal Coreto a version that resolves this vulnerability.Fixed in 8.5.1
Event History
Frequently Asked Questions
What is CVE-2018-7600?
CVE-2018-7600 is a vulnerability in Drupal Core that allows remote attackers to execute arbitrary code.
Which versions of Drupal are affected by CVE-2018-7600?
Drupal versions before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 are affected by CVE-2018-7600.
How severe is CVE-2018-7600?
CVE-2018-7600 has a severity rating of 9.8 out of 10.
How can I fix CVE-2018-7600?
To fix CVE-2018-7600, update Drupal Core to version 7.58, 8.3.9, 8.4.6, or 8.5.1.
Where can I find more information about CVE-2018-7600?
You can find more information about CVE-2018-7600 at the following references: [link 1](https://www.drupal.org/sa-core-2018-002), [link 2](http://www.securityfocus.com/bid/103534), [link 3](http://www.securitytracker.com/id/1040598).