Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDrupal
APPDrupal8.0.0 – 8.9.19 (excl.)9.1.0 – 9.1.13 (excl.)9.2.0 – 9.2.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2018-7602CRITICAL9.8⚠ KEVPL ✓same product
RCE w Drupal 7.x i 8.x — zdalne wykonanie kodu (Drupalgeddon2 follow-up)
CVE-2018-7600CRITICAL9.8⚠ KEVPL ✓same product
Drupalgeddon 2 — zdalne wykonanie kodu w Drupal (RCE)
CVE-2024-55637CRITICAL9.8PL ✓same product
Deserializacja niezaufanych danych w Drupal Core umożliwia RCE
CVE-2024-55636CRITICAL9.8PL ✓same product
Deserialization podatności w Drupal Core umożliwiająca RCE (Object Injection)
CVE-2024-55638CRITICAL9.8PL ✓same product
Deserialization gadget chain w Drupal Core umożliwiający RCE