First published: Wed Feb 20 2019(Updated: )
Highly critical - Remote Code Execution
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=7.0.0<7.62.0>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.11>=8.6.0<8.6.10 | |
composer/drupal/drupal | >=7.0.0<7.62.0>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.11>=8.6.0<8.6.10 | |
composer/drupal/drupal | >=8.6.0<8.6.10 | 8.6.10 |
composer/drupal/drupal | >=8.0.0<8.5.11 | 8.5.11 |
composer/drupal/drupal | >=7.0.0<7.62.0 | 7.62.0 |
composer/drupal/core | >=8.0.0<8.5.11 | 8.5.11 |
composer/drupal/core | >=7.0.0<7.62.0 | 7.62.0 |
composer/drupal/core | >=8.6.0<8.6.10 | 8.6.10 |
Drupal | >=8.5.0<8.5.11 | |
Drupal | >=8.6.0<8.6.10 | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6340 is classified as highly critical due to its potential for remote code execution.
To remediate CVE-2019-6340, update Drupal to version 7.62.0, 8.5.11, or 8.6.10 or later.
CVE-2019-6340 affects Drupal versions from 7.0.0 to 7.62.0, and 8.0.0 to 8.6.10.
CVE-2019-6340 is a remote code execution vulnerability that allows arbitrary PHP code execution in certain cases.
Yes, CVE-2019-6340 arises from field types in Drupal that do not properly sanitize data from non-form sources.