CVE Vulnerabilities

CVE-2019-6342

Published: May 28, 2020 | Modified: Jul 21, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 8.7.4 (including) 8.7.4 (including)
Drupal7 Ubuntu esm-apps/xenial *
Drupal7 Ubuntu esm-infra-legacy/trusty *
Drupal7 Ubuntu trusty *
Drupal7 Ubuntu trusty/esm *
Drupal7 Ubuntu xenial *

References