CVE-2017-6922
- EPSS 2.72%
- Veröffentlicht 22.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:49
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rathe...
CVE-2017-6923
- EPSS 0.85%
- Veröffentlicht 22.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:49
In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is m...
CVE-2019-6339
- EPSS 80.78%
- Veröffentlicht 22.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:26
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code...
- EPSS 1.09%
- Veröffentlicht 22.01.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:26
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-20...
CVE-2017-6921
- EPSS 0.55%
- Veröffentlicht 15.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:48
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is enabled and a...
CVE-2017-6924
- EPSS 0.58%
- Veröffentlicht 15.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:49
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RE...
CVE-2017-6925
- EPSS 0.65%
- Veröffentlicht 15.01.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:49
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs, and entit...
CVE-2017-6920
- EPSS 67.04%
- Veröffentlicht 06.08.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:48
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
CVE-2018-14773
- EPSS 16.65%
- Veröffentlicht 03.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:45
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets us...
CVE-2018-7602
- EPSS 94.32%
- Veröffentlicht 19.07.2018 17:29:00
- Zuletzt bearbeitet 07.11.2025 19:18:37
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability...