CVE-2024-11942: Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002
A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.
Other sources
Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.
The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11942?
The severity of CVE-2024-11942 is considered high due to its potential impact on file manipulation capabilities.
How do I fix CVE-2024-11942?
To mitigate CVE-2024-11942, upgrade your Drupal Core to version 10.2.10 or higher.
Which Drupal versions are affected by CVE-2024-11942?
CVE-2024-11942 affects Drupal Core versions from 10.0.0 up to 10.2.10.
What type of vulnerability is CVE-2024-11942?
CVE-2024-11942 is a vulnerability that allows file manipulation in Drupal Core.
What module is involved in CVE-2024-11942?
The bug in CVE-2024-11942 is related to the CKEditor 5 module in Drupal.