First published: Tue Jan 15 2019(Updated: )
Critical - Third Party Libraries
Credit: mlhess@drupal.org mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/drupal | >=7.0.0<7.62.0>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.9>=8.6.0<8.6.6 | |
composer/drupal/core | >=7.0.0<7.62.0>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.9>=8.6.0<8.6.6 | |
debian/drupal7 | ||
composer/drupal/drupal | >=8.6.0<8.6.6 | 8.6.6 |
composer/drupal/drupal | >=8.0.0<8.5.9 | 8.5.9 |
composer/drupal/drupal | >=7.0.0<7.62.0 | 7.62.0 |
Drupal | >=7.0<7.62 | |
Drupal | >=8.5.0<8.5.9 | |
Drupal | >=8.6.0<8.6.6 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6338 is considered a critical vulnerability affecting specific versions of Drupal due to the use of an outdated third-party library.
To resolve CVE-2019-6338, you should update your Drupal installation to version 7.62, 8.5.9, or 8.6.6.
CVE-2019-6338 affects Drupal core versions 7.x prior to 7.62, 8.5.x prior to 8.5.9, and 8.6.x prior to 8.6.6.
The vulnerability may allow attackers to exploit configurations that use the affected library, potentially leading to unauthorized access or data manipulation.
It is recommended that all users of affected Drupal versions upgrade to the latest patched version immediately to mitigate security risks.