First published: Tue Jan 15 2019(Updated: )
Critical - Arbitrary PHP code execution
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/drupal | >=7.0.0<7.62.0>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.9>=8.6.0<8.6.6 | |
composer/drupal/core | >=7.0.0<7.62.0>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.9>=8.6.0<8.6.6 | |
debian/drupal7 | ||
composer/drupal/core | >=8.6.0<8.6.6 | 8.6.6 |
composer/drupal/core | >=8.0.0<8.5.9 | 8.5.9 |
composer/drupal/core | >=7.0.0<7.62.0 | 7.62.0 |
composer/drupal/drupal | >=8.6.0<8.6.6 | 8.6.6 |
composer/drupal/drupal | >=8.0.0<8.5.9 | 8.5.9 |
composer/drupal/drupal | >=7.0.0<7.62.0 | 7.62.0 |
Drupal | >=7.0<7.62 | |
Drupal | >=8.5.0<8.5.9 | |
Drupal | >=8.6.0<8.6.6 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6339 has been classified as a critical vulnerability due to its potential for arbitrary PHP code execution.
To fix CVE-2019-6339, update your Drupal installation to version 7.62 or later, 8.5.9 or later, or 8.6.6 or later.
CVE-2019-6339 affects Drupal Core versions 7.x prior to 7.62, 8.5.x prior to 8.5.9 and 8.6.x prior to 8.6.6.
Yes, CVE-2019-6339 can be exploited remotely, making it accessible to malicious actors.
If your Drupal site is vulnerable to CVE-2019-6339, immediately apply the necessary updates to mitigate the issue.