PT-2017-17026 · Drupal · Drupal

Timo Hilsdorf

·

Publicado

2017-03-16

·

Atualizado

2022-05-13

·

CVE-2017-6381

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drupal versions prior to 8.2.2
Description A third-party development library included with Drupal 8 development dependencies is susceptible to remote code execution. However, this issue is mitigated by the default .htaccess protection against PHP execution and the fact that Composer development dependencies are not normally installed.
Recommendations For versions prior to 8.2.2, consider removing the /vendor/phpunit directory from production deployments to mitigate the risk.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6381
GHSA-RHX9-3QF7-R3J7

Produtos afetados

Drupal