Vulnerability Bulletins

Drupal core - Moderately critical - Third-party library - SA-CORE-2020-001


System information

   
Affected software Drupal

Description

Project: Drupal coreVersion: 8.8.x-dev8.7.x-devDate: 2020-March-18Security risk: Moderately critical 13∕25 AC:Complex/A:User/CI:Some/II:Some/E:Proof/TD:DefaultVulnerability: Third-party libraryDescription: The Drupal project uses the third-party library CKEditor, which has released a security improvement that is needed to protect some Drupal configurations.Vulnerabilities are possible if Drupal is configured to use the WYSIWYG CKEditor for your sites users. An attacker that can create or

More info:

https://www.drupal.org/sa-core-2020-001

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2020-03-20
Ministerio de Defensa
CNI
CCN
CCN-CERT