Boletines de Vulnerabilidades

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2019-003


Información sobre el sistema

   
Software afectado Drupal

Descripción

Project: Drupal coreDate: 2019-February-20Security risk: Highly critical 23∕25 AC:None/A:None/CI:All/II:All/E:Exploit/TD:UncommonVulnerability: Remote Code ExecutionCVE IDs: CVE-2019-6340Description: Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.A site is only affected by this if one of the following conditions is met:The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows

More info:

https://www.drupal.org/sa-core-2019-003

Identificadores estándar

Propiedad Valor
CVE CVE-2019-6340.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2019-04-08

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT