First published: Tue Jul 16 2019(Updated: )
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >8.7.3<8.7.5 | |
composer/drupal/drupal | >8.7.3<8.7.5 | |
Drupal Drupal | =8.7.4 | |
composer/drupal/drupal | >8.7.3<8.7.5 | 8.7.5 |
composer/drupal/core | >8.7.3<8.7.5 | 8.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6342 is critical.
CVE-2019-6342 affects Drupal Core versions 8.7.3 to 8.7.5.
CVE-2019-6342 is an Access Bypass vulnerability.
To fix CVE-2019-6342 in Drupal Core, you should upgrade to version 8.7.6.
You can find more information about CVE-2019-6342 on the Drupal website at https://www.drupal.org/sa-core-2019-008.