CVE Vulnerabilities

CVE-2019-6342

Published: May 28, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal8.7.4 (including)8.7.4 (including)
Drupal7Ubuntuesm-apps/xenial*
Drupal7Ubuntuesm-infra-legacy/trusty*
Drupal7Ubuntutrusty*
Drupal7Ubuntutrusty/esm*
Drupal7Ubuntuxenial*

References