First published: Wed Sep 16 2020(Updated: )
Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.10>=8.9.0<8.9.6>=9.0.0<9.0.6 | |
composer/drupal/drupal | >=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.10>=8.9.0<8.9.6>=9.0.0<9.0.6 | |
Drupal Drupal | >=8.8.0<8.8.10 | |
Drupal Drupal | >=8.9.0<8.9.6 | |
Drupal Drupal | >=9.0.0<9.0.6 | |
composer/drupal/drupal | >=9.0.0<9.0.6 | 9.0.6 |
composer/drupal/drupal | >=8.9.0<8.9.6 | 8.9.6 |
composer/drupal/drupal | >=8.0.0<8.8.10 | 8.8.10 |
composer/drupal/core | >=9.0.0<9.0.6 | 9.0.6 |
composer/drupal/core | >=8.9.0<8.9.6 | 8.9.6 |
composer/drupal/core | >=8.0.0<8.8.10 | 8.8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-13668 is medium.
The affected software for CVE-2020-13668 is Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
An attacker can exploit CVE-2020-13668 by leveraging the way that HTML is rendered for affected forms in Drupal Core.
The Common Weakness Enumeration (CWE) for CVE-2020-13668 is CWE-79.
You can find more information about CVE-2020-13668 on the Drupal website at https://www.drupal.org/sa-core-2020-009.