PT-2019-4535 · Drupal · Drupal Views Dynamic Fields

Br0X

·

Published

2019-12-16

·

Updated

2019-12-27

·

CVE-2019-19826

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drupal Views Dynamic Fields module versions prior to 7.x-1.0-alpha4
Description The issue is related to insufficient deserialization mechanisms in the handlers/views handler filter dynamic fields.inc component of the Views Dynamic Fields module for the Drupal CMS. This can be exploited by a remote attacker to potentially execute arbitrary code. The vulnerability involves insecure unserialize calls, which can lead to PHP object injection. This might allow for file deletion and possibly code execution, involving objects such as field names and Archive Tar.
Recommendations For versions prior to 7.x-1.0-alpha4, update to a version that includes a fix for the insecure deserialization issue in the handlers/views handler filter dynamic fields.inc component. As a temporary workaround, consider restricting access to the handlers/views handler filter dynamic fields.inc file to minimize the risk of exploitation. Avoid using the field names object and the Archive Tar object in the affected module until the issue is resolved.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00575
CVE-2019-19826

Affected Products

Drupal Views Dynamic Fields