CVE-2019-6340: Drupal Core Remote Code Execution Vulnerability

Published Feb 20, 2019
·
Updated

Highly critical - Remote Code Execution

Other sources

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

CISA

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

Affected Software

11 affected componentsFixes available
composer/drupal/core>=7.0.0, <7.62.0, >=8.0.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.4.0, >=8.4.0, <8.5.0, >=8.5.0, <8.5.11, >=8.6.0, <8.6.10
composer/drupal/drupal>=7.0.0, <7.62.0, >=8.0.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.4.0, >=8.4.0, <8.5.0, >=8.5.0, <8.5.11, >=8.6.0, <8.6.10
composer/drupal/drupal>=8.6.0<8.6.10
8.6.10
composer/drupal/drupal>=8.0.0<8.5.11
8.5.11
composer/drupal/drupal>=7.0.0<7.62.0
7.62.0
composer/drupal/core>=8.0.0<8.5.11
8.5.11
composer/drupal/core>=7.0.0<7.62.0
7.62.0
composer/drupal/core>=8.6.0<8.6.10
8.6.10
Drupal Core
Drupal Drupal>=8.5.0<8.5.11
Drupal Drupal>=8.6.0<8.6.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/drupal/drupal to a version that resolves this vulnerability.

    Fixed in 8.6.10
  2. Upgrade

    Upgrade composer/drupal/drupal to a version that resolves this vulnerability.

    Fixed in 8.5.11
  3. Upgrade

    Upgrade composer/drupal/drupal to a version that resolves this vulnerability.

    Fixed in 7.62.0
  4. Upgrade

    Upgrade composer/drupal/core to a version that resolves this vulnerability.

    Fixed in 8.5.11
  5. Upgrade

    Upgrade composer/drupal/core to a version that resolves this vulnerability.

    Fixed in 7.62.0
  6. Upgrade

    Upgrade composer/drupal/core to a version that resolves this vulnerability.

    Fixed in 8.6.10
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.5.11
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.6.10
  9. Compensating control

    If Services (Drupal 7) or Drupal 8 RESTful Web Services (rest) / other web services modules (e.g., JSON:API) are enabled, restrict PATCH or POST requests to limit exposure to the Remote Code Execution vulnerability.

Event History

Feb 20, 2019
Advisory Published
05:41 PM
Feb 21, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 25, 2022
Known Exploited
via CISA·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-6340?

CVE-2019-6340 is classified as highly critical due to its potential for remote code execution.

2

How do I fix CVE-2019-6340?

To remediate CVE-2019-6340, update Drupal to version 7.62.0, 8.5.11, or 8.6.10 or later.

3

What versions of Drupal are affected by CVE-2019-6340?

CVE-2019-6340 affects Drupal versions from 7.0.0 to 7.62.0, and 8.0.0 to 8.6.10.

4

What kind of vulnerability is CVE-2019-6340?

CVE-2019-6340 is a remote code execution vulnerability that allows arbitrary PHP code execution in certain cases.

5

Is CVE-2019-6340 related to data sanitization issues?

Yes, CVE-2019-6340 arises from field types in Drupal that do not properly sanitize data from non-form sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203