SA-CORE-2024-002: Critical severity Drupal Drupal vulnerability
Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site. The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of SA-CORE-2024-002?
SA-CORE-2024-002 is classified as a critical severity vulnerability due to the potential for file system manipulation.
How do I fix SA-CORE-2024-002?
To fix SA-CORE-2024-002, users must upgrade to Drupal version 10.2.11 or later.
What software is affected by SA-CORE-2024-002?
SA-CORE-2024-002 affects Drupal versions up to and including 10.2.10.
Can SA-CORE-2024-002 be exploited by a malicious user?
Yes, under certain site configurations, SA-CORE-2024-002 can be exploited by a malicious user to disrupt a website.
What module is involved in the SA-CORE-2024-002 vulnerability?
The vulnerability involves a bug in the CKEditor 5 module used in Drupal.