CVE-2019-6339
9.8
CRITICAL · CVSS 3.0 · EPSS 35.6% (pctl 98)
Patch early
EPSS 35.6% — above the 10% action threshold.
Description
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 35.58% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-01-22 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| drupal | drupal |
References
- https://lists.debian.org/debian-lts-announce/2019/02/msg00004.html
- https://www.debian.org/security/2019/dsa-4370
- https://www.drupal.org/sa-core-2019-002
- https://lists.debian.org/debian-lts-announce/2019/02/msg00004.html
- https://www.debian.org/security/2019/dsa-4370
- https://www.drupal.org/sa-core-2019-002
→ the Explorer · watch your stack · NVD