First published: Mon Nov 11 2019(Updated: )
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Svg Sanitizer | <=7.x-1.5 | |
Drupal Svg Sanitizer | =8.x-1.0-alpha1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18856 is classified as a Denial of Service vulnerability.
To fix CVE-2019-18856, update the Drupal SVG Sanitizer module to a version that addresses this vulnerability.
CVE-2019-18856 affects Drupal SVG Sanitizer versions 8.x-1.0-alpha1 and 7.x-1.5 and earlier.
CVE-2019-18856 is caused by mishandling access to external resources via the SVG use element in the SVG Sanitizer module.
Currently, the best approach for CVE-2019-18856 is to patch your software rather than seeking a workaround.