CVE-2019-6342: Drupal core - Critical - Access bypass - SA-CORE-2019-008
Published Jul 16, 2019
·Updated
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
Affected Software
5 affected componentsFixes available
composer/drupal/core>8.7.3, <8.7.5
composer/drupal/drupal>8.7.3, <8.7.5
composer/drupal/drupal>8.7.3<8.7.5
8.7.5
composer/drupal/core>8.7.3<8.7.5
8.7.5
Drupal Drupal=8.7.4
Event History
Jul 16, 2019
Advisory Published
04:24 PM
May 28, 2020
CVE Published
via MITRE·08:59 PM
Data Sourced
via MITRE·08:59 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6342?
The severity of CVE-2019-6342 is critical.
2
How does CVE-2019-6342 affect Drupal Core?
CVE-2019-6342 affects Drupal Core versions 8.7.3 to 8.7.5.
3
What is the vulnerability type of CVE-2019-6342?
CVE-2019-6342 is an Access Bypass vulnerability.
4
How can I fix CVE-2019-6342 in Drupal Core?
To fix CVE-2019-6342 in Drupal Core, you should upgrade to version 8.7.6.
5
Where can I find more information about CVE-2019-6342?
You can find more information about CVE-2019-6342 on the Drupal website at https://www.drupal.org/sa-core-2019-008.