First published: Wed Jul 20 2022(Updated: )
Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2022-014
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.9.0<8.10.0>=9.0.0<9.1.0>=9.1.0<9.2.0>=9.2.0<9.3.0>=9.3.0<9.3.19>=9.4.0<9.4.3 | |
Drupal Drupal | >=8.0.0<9.3.19 | |
Drupal Drupal | >=9.4.0<9.4.3 | |
composer/drupal/core | >=9.4.0<9.4.3 | 9.4.3 |
composer/drupal/core | >=8.0.0<9.3.19 | 9.3.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Drupal vulnerability is CVE-2022-25277.
The severity of CVE-2022-25277 is high with a CVSS score of 7.2.
CVE-2022-25277 affects Drupal versions 8.9.0 up to 8.10.0, 9.0.0 up to 9.1.0, 9.1.0 up to 9.2.0, 9.2.0 up to 9.3.0, 9.3.0 up to 9.3.19, and 9.4.0 up to 9.4.3.
CVE-2022-25277 allows an attacker to execute arbitrary PHP code.
To fix the vulnerability CVE-2022-25277, it is recommended to update Drupal core to a version that includes the patch provided in SA-CORE-2022-014.