peter bassill · operator
$ cve CVE-2019-6339 JSON

CVE-2019-6339

9.8
CRITICAL · CVSS 3.0 · EPSS 35.6% (pctl 98)

Patch early

EPSS 35.6% — above the 10% action threshold.

Description

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS35.58% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2019-01-22
Last modified2026-06-17

Affected (2)

VendorProduct
debiandebian linux
drupaldrupal

References

→ the Explorer  ·  watch your stack  ·  NVD