peter bassill · operator
$ cve CVE-2019-6340 JSON

CVE-2019-6340 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 92% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS92.02% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2019-02-21
Last modified2026-06-17

CISA KEV

NameDrupal Core Remote Code Execution Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productDrupal / Core
Ransomware usenone reported

Affected (1)

VendorProduct
drupaldrupal

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD