Drupal core - Highly critical - Remote Code Execution
100Vexday Risk Score
Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.
ssvc Actcvss 8.1epss 92%
da publicação à arma1 dias
Publicada no NVD21 de fev.
1ª PoC+1d
metasploit20 de fev.
CISA KEV+1128d
probabilidade de exploração
92%top 1% das CVEs
exploração observada
simCISA + VulnCheck
23 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2022-04-15
Apply updates per vendor instructions.
Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Drupal · Drupal CorePoCs públicas encontradas — 23✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46510exploitdbwww.exploit-db.com/exploits/46459não verificadoexploitdbwww.exploit-db.com/exploits/46452não verificadogithubgithub.com/jas502n/CVE-2019-6340★ 71githubgithub.com/knqyf263/CVE-2019-6340★ 42githubgithub.com/g0rx/Drupal-SA-CORE-2019-003★ 32githubgithub.com/oways/CVE-2019-6340★ 12githubgithub.com/ludy-dev/drupal8-REST-RCE★ 4githubgithub.com/DevDungeon/CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass★ 2githubgithub.com/joaoaugustom/Drupal_REST-RCE_Unauthenticated★ 0githubgithub.com/cved-sources/cve-2019-6340★ 0githubgithub.com/josehelps/cve-2019-6340-bits★ 0githubgithub.com/nobodyatall648/CVE-2019-6340★ 0githubgithub.com/Sumitpathania03/Drupal-cve-2019-6340★ 0vulncheckvulncheck.com/xdb/0064453ac8c0não verificadocve_referencewww.exploit-db.com/exploits/46459/não verificadocve_referencewww.exploit-db.com/exploits/46510/não verificadovulncheckvulncheck.com/xdb/5aa4db1c5af5não verificadovulncheckvulncheck.com/xdb/313b5dedfaeenão verificadovulncheckvulncheck.com/xdb/971bb71f8accnão verificadovulncheckvulncheck.com/xdb/b716c66caa48não verificadovulncheckvulncheck.com/xdb/e32101bbe942não verificadocve_referencewww.exploit-db.com/exploits/46452/não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6340https://www.drupal.org/sa-core-2019-003https://www.exploit-db.com/exploits/46452/https://www.exploit-db.com/exploits/46459/https://www.exploit-db.com/exploits/46510/https://www.synology.com/security/advisory/Synology_SA_19_09http://www.securityfocus.com/bid/107106