drupal/core Security Advisories for 8.5.2 (42)
-
[LOW] Drupal Full Path Disclosure
PKSA-styk-3knc-d1bt CVE-2024-45440 GHSA-mg8j-w93w-xjgc
Affected version: >=8.0.0,<10.2.9|>=10.3.0,<10.3.6|>=11.0.0,<11.0.5
Reported by:
GitHub -
[MEDIUM] Drupal core - Moderately critical - Denial of Service
PKSA-2gfj-5sh8-j3c5 GHSA-f84q-mgj9-8jfc
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.9.0|>=8.9.0,<9.0.0|>=9.0.0,<9.1.0|>=9.1.0,<9.2.0|>=9.2.0,<9.3.0|>=9.3.0,<9.4.0|>=9.4.0,<9.5.0|>=9.5.0,<10.0.0|>=10.0.0,<10.1.0|>=10.1.0,<10.1.8|>=10.2.0,<10.2.2
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Improper input validation in Drupal core
PKSA-fpcy-trdp-tpy2 CVE-2022-25273 GHSA-g36h-4jr6-qmm9
Affected version: >=9.3.0,<9.3.12|>=8.0.0,<9.2.18
Reported by:
GitHub -
[MEDIUM] Lack of domain validation in Druple core
PKSA-4j5n-cxxv-ptjc CVE-2022-25276 GHSA-4wfq-jc9h-vpcx
Affected version: >=9.4.0,<9.4.3|>=8.0.0,<9.3.19
Reported by:
GitHub -
[MEDIUM] Drupal core - Moderately critical - Access Bypass - SA-CORE-2022-013
PKSA-gkkw-qh7h-5181 CVE-2022-25278 GHSA-cfh2-7f6h-3m85
Affected version: >=8.0.0,<9.3.19|>=9.4.0,<9.4.3
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Improper input validation in Drupal core
PKSA-72rg-qbp7-873g CVE-2022-25271 GHSA-fmfv-x8mp-5767
Affected version: >=7.0.0,<7.88|>=8.0.0,<9.2.13|>=9.3.0,<9.3.6
Reported by:
GitHub -
[MEDIUM] Incorrect authorization in Drupal core
PKSA-2tvs-gcpz-cmm6 CVE-2022-25270 GHSA-73q4-j324-2qcc
Affected version: >=8.0.0,<9.2.13|>=9.3.0,<9.3.6
Reported by:
GitHub -
[CRITICAL] Unrestricted Upload of File with Dangerous Type in Drupal core
PKSA-46zx-gs68-q4zv CVE-2020-13675 GHSA-v8wr-r69p-mmwx
Affected version: >=8.0.0,<8.9.19|>=9.2.0,<9.2.6|>=9.1.0,<9.1.13
Reported by:
GitHub -
[MEDIUM] Cross-Site Request Forgery in Drupal core
PKSA-4q53-3jd6-45wg CVE-2020-13674 GHSA-j586-cj67-vg4p
Affected version: >=8.0.0,<8.9.19|>=9.2.0,<9.2.6|>=9.1.0,<9.1.13
Reported by:
GitHub -
[HIGH] Drupal core access bypass vulnerability
PKSA-njy4-5vnq-bx5f CVE-2020-13677 GHSA-3xr3-phjp-g6p2
Affected version: >=9.2.0,<9.2.6|>=9.1.0,<9.1.13|>=8.0.0,<8.9.19
Reported by:
GitHub -
[MEDIUM] Incorrect Authorization in Drupal core
PKSA-s6ck-qn9j-xnqf CVE-2020-13676 GHSA-qfhg-m6r8-xxpj
Affected version: >=8.0.0,<8.9.19|>=9.2.0,<9.2.6|>=9.1.0,<9.1.13
Reported by:
GitHub -
[MEDIUM] Drupal core - Moderately critical - Third-party libraries - SA-CORE-2021-005
PKSA-6dxs-yv9z-8twp GHSA-7f4f-p7mq-p4fv
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.9.0|>=8.9.0,<8.9.16|>=9.0.0,<9.1.0|>=9.1.0,<9.1.12|>=9.2.0,<9.2.4
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Critical - Cross-site scripting - SA-CORE-2021-002
PKSA-7zvx-63nf-7nkj CVE-2020-13672 GHSA-3m36-mjwj-352c
Affected version: >=7.0.0,<7.80|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.9.0|>=8.9.0,<8.9.14|>=9.0.0,<9.0.12|>=9.1.0,<9.1.7
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Critical - Cross-site scripting - SA-CORE-2021-003
PKSA-bc4x-jnrh-4k6w CVE-2021-33829 GHSA-rgx6-rjj4-c388
Affected version: >=7.0.0,<7.80|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.9.0|>=8.9.0,<8.9.16|>=9.0.0,<9.0.14|>=9.1.0,<9.1.9
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2020-013
PKSA-kjgx-r4v3-961f GHSA-gfvf-2f25-f34r
Affected version: >=7.0.0,<7.74|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.11|>=8.9.0,<8.9.9|>=9.0.0,<9.0.8
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Drupal core - Critical - Remote code execution - SA-CORE-2020-012
PKSA-77t6-rxnw-bfjm CVE-2020-13671 GHSA-68jc-v27h-vhmw
Affected version: >=7.0.0,<7.74|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.11|>=8.9.0,<8.9.9|>=9.0.0,<9.0.8
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Moderately critical - Access bypass - SA-CORE-2020-008
PKSA-jknr-sjbw-zn24 CVE-2020-13667 GHSA-x2q9-r8gm-f657
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.10|>=8.9.0,<8.9.6|>=9.0.0,<9.0.6
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2020-007
PKSA-c6qk-kgrx-8q42 CVE-2020-13666 GHSA-8jj2-x2gc-ggm7
Affected version: >=7.0.0,<7.73|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.10|>=8.9.0,<8.9.6|>=9.0.0,<9.0.6
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Critical - Cross-site scripting - SA-CORE-2020-009
PKSA-1k26-dn58-yzpc CVE-2020-13668 GHSA-m6q5-wv4x-fv6h
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.10|>=8.9.0,<8.9.6|>=9.0.0,<9.0.6
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2020-010
PKSA-69gr-9b59-5f99 CVE-2020-13669 GHSA-c533-c843-67h8
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.10|>=8.9.0,<8.9.6|>=9.0.0,<9.0.6
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Drupal core - Moderately critical - Information disclosure - SA-CORE-2020-011
PKSA-ggc3-34xd-zmzd CVE-2020-13670 GHSA-mmjr-5q74-p3m4
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.10|>=8.9.0,<8.9.6|>=9.0.0,<9.0.6
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[CRITICAL] Drupal core - Critical - Cross Site Request Forgery - SA-CORE-2020-004
PKSA-j215-hxck-vk25 CVE-2020-13663 GHSA-m648-hpf8-qcjw
Affected version: >=7.0.0,<7.72|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.8|>=8.9.0,<8.9.1|>=9.0.0,<9.0.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2020-005
PKSA-jkzg-rr1r-vmvy CVE-2020-13664 GHSA-x72f-ggjw-v5xh
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.8|>=8.9.0,<8.9.1|>=9.0.0,<9.0.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[CRITICAL] Drupal core - Less critical - Access bypass - SA-CORE-2020-006
PKSA-5wmm-s575-4sjg CVE-2020-13665 GHSA-wxqp-jwc9-g39x
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.8.0|>=8.8.0,<8.8.8|>=8.9.0,<8.9.1|>=9.0.0,<9.0.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002
PKSA-yxnf-v37t-gh27 CVE-2020-13662 GHSA-gjqg-9rhv-qj67
Affected version: >=7.0.0,<7.70|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.7.14|>=8.8.0,<8.8.6
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Moderately critical - Third-party library - SA-CORE-2020-001
PKSA-rb2t-qsk8-f792 GHSA-mh4h-27gq-cxwj
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.7.12|>=8.8.0,<8.8.4
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Moderately critical - Multiple vulnerabilities - SA-CORE-2019-010
PKSA-xv6s-sqg3-tq2g GHSA-7gwj-7fhm-vw4w
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.7.11|>=8.8.0,<8.8.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[CRITICAL] Drupal core - Moderately critical - Access bypass - SA-CORE-2019-011
PKSA-vcbr-zg2g-wfsp GHSA-6mgp-v5cm-ghg5
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.7.11|>=8.8.0,<8.8.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[CRITICAL] Drupal core - Moderately critical - Denial of Service - SA-CORE-2019-009
PKSA-n8hw-tywm-xrh7 GHSA-7v68-3pr5-h3cr
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.7.11|>=8.8.0,<8.8.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Critical - Multiple vulnerabilities - SA-CORE-2019-012
PKSA-mw8j-f3jc-m8zf GHSA-pr99-c33p-fwf6
Affected version: >=7.0.0,<7.69|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.7.0|>=8.7.0,<8.7.11|>=8.8.0,<8.8.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[CRITICAL] Moderately critical - Third-party libraries - SA-CORE-2019-007
PKSA-75yj-2hm1-2ffx CVE-2019-11831 GHSA-xv7v-rf6g-xwrc
Affected version: >=7.0.0,<7.67.0|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.6.0|>=8.6.0,<8.6.16|>=8.7.0,<8.7.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Drupal core - Moderately critical - Multiple Vulnerabilities - SA-CORE-2019-005
PKSA-q3jn-2tvt-kmzh CVE-2019-10909 GHSA-g996-q5r8-w7g2
Affected version: >=7.0,<7.65|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.14|>=8.6.0,<8.6.14
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Moderately critical - Cross Site Scripting - SA-CORE-2019-004
PKSA-ycp7-r1gf-k17h CVE-2019-6341 GHSA-cmmh-8mwp-gq5p
Affected version: >=7.0.0,<7.65.0|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.14|>=8.6.0,<8.6.13
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Highly critical - Remote Code Execution
PKSA-18ct-8ggk-h581 CVE-2019-6340 GHSA-3gx6-h57h-rm27
Affected version: >=7.0.0,<7.62.0|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.11|>=8.6.0,<8.6.10
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[CRITICAL] Critical - Arbitrary PHP code execution
PKSA-9n1q-yjxq-ntxd CVE-2019-6339 GHSA-8cw5-rv98-5c46
Affected version: >=7.0.0,<7.62.0|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.9|>=8.6.0,<8.6.6
Reported by:
FriendsOfPHP/security-advisories, GitHub -
Critical - Third Party Libraries
PKSA-tqjg-2d31-rxds CVE-2019-6338
Affected version: >=7.0.0,<7.62.0|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.9|>=8.6.0,<8.6.6
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] External URL injection through URL aliases - Moderately Critical - Open Redirect
PKSA-254t-dtnb-4ybb GHSA-vfgc-c76h-mwh4
Affected version: >=7.0,<7.60|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.8|>=8.6.0,<8.6.2
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Injection in DefaultMailSystem::mail() - Critical - Remote Code Execution
PKSA-mhgf-dg9m-23xj GHSA-6ccv-8fgf-cjpw
Affected version: >=7.0,<7.60|>=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.8|>=8.6.0,<8.6.2
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Anonymous Open Redirect - Moderately Critical - Open Redirect
PKSA-1723-b3b5-yrdh GHSA-gxxj-g9v8-w28p
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.8|>=8.6.0,<8.6.2
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Contextual Links validation - Critical - Remote Code Execution
PKSA-mkhd-5d73-ftb7 GHSA-6gf6-24h2-66j4
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.8|>=8.6.0,<8.6.2
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Content moderation - Moderately critical - Access bypass
PKSA-7ptn-7539-yr8y GHSA-98h9-727m-44qv
Affected version: >=8.0.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4.0,<8.5.0|>=8.5.0,<8.5.8|>=8.6.0,<8.6.2
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[CRITICAL] Critical - Remote Code Execution
PKSA-xw62-8xjy-mc59 CVE-2018-7602 GHSA-297x-j9pm-xjgg
Affected version: >=7.0,<7.59|>=8.0,<8.1.0|>=8.1.0,<8.2.0|>=8.2.0,<8.3.0|>=8.3.0,<8.4.0|>=8.4,<8.4.8|>=8.5,<8.5.3
Reported by:
FriendsOfPHP/security-advisories, GitHub