A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Drupal | Drupal | 7.0 (including) | 7.59 (excluding) |
Drupal | Drupal | 8.4.0 (including) | 8.4.8 (excluding) |
Drupal | Drupal | 8.5.0 (including) | 8.5.3 (excluding) |
Drupal7 | Ubuntu | artful | * |
Drupal7 | Ubuntu | esm-apps/xenial | * |
Drupal7 | Ubuntu | trusty | * |
Drupal7 | Ubuntu | trusty/esm | * |
Drupal7 | Ubuntu | upstream | * |
Drupal7 | Ubuntu | xenial | * |