CVE Vulnerabilities

CVE-2019-6342

Published: May 28, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 8.7.4 (including) 8.7.4 (including)
Drupal7 Ubuntu esm-apps/xenial *
Drupal7 Ubuntu esm-infra-legacy/trusty *
Drupal7 Ubuntu trusty *
Drupal7 Ubuntu trusty/esm *
Drupal7 Ubuntu xenial *

References