CVE-2019-6338: third-party PEAR Archive_Tar library updates
Critical - Third Party Libraries
Other sources
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR ArchiveTar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6338?
CVE-2019-6338 is considered a critical vulnerability affecting specific versions of Drupal due to the use of an outdated third-party library.
How do I fix CVE-2019-6338?
To resolve CVE-2019-6338, you should update your Drupal installation to version 7.62, 8.5.9, or 8.6.6.
Which versions of Drupal are affected by CVE-2019-6338?
CVE-2019-6338 affects Drupal core versions 7.x prior to 7.62, 8.5.x prior to 8.5.9, and 8.6.x prior to 8.6.6.
What is the impact of CVE-2019-6338 on my website?
The vulnerability may allow attackers to exploit configurations that use the affected library, potentially leading to unauthorized access or data manipulation.
Is there a recommended action for users of Drupal due to CVE-2019-6338?
It is recommended that all users of affected Drupal versions upgrade to the latest patched version immediately to mitigate security risks.