VDB
Sign up
—

DRUPAL-CORE-2018-002

Quick fix

DRUPAL-CORE-2018-002 — drupal/core: upgrade to the fixed version with the command below.

composer require drupal/core:^8.3.9

Details

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.

The security team has written an [FAQ](https://groups.drupal.org/security/faq-2018-002) about this issue.

*Edited 2020, February 13 to fix links to patch files.*

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/drupal/core
Introduced in: 8.0.0Fixed in: 8.3.9
Fixcomposer require drupal/core:^8.3.9

References