Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68jc-v27h-vhmw

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Drupal core Unrestricted Upload of File with Dangerous Type

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.0.8

9.0.8

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.9.0, < 8.9.9

8.9.9

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.0.0, < 8.8.11

8.8.11

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.74

7.74

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.74

7.74

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 8.0.0, < 8.8.11

8.8.11

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 8.9.0, < 8.9.9

8.9.9

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.0.8

9.0.8

EPSS

Процентиль: 88%
0.04323
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
nvd
больше 4 лет назад

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
debian
больше 4 лет назад

Drupal core does not properly sanitize certain filenames on uploaded f ...

CVSS3: 9.9
fstec
больше 4 лет назад

Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 88%
0.04323
Низкий

8.8 High

CVSS3

Дефекты

CWE-434