VDB
Sign up
—

DRUPAL-CORE-2018-004

Quick fix

DRUPAL-CORE-2018-004 — drupal/core: upgrade to the fixed version with the command below.

composer require drupal/core:^8.4.8

Details

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to [Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002](/sa-core-2018-002). Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

*Updated — this vulnerability is being exploited in the wild.*

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/drupal/core
Introduced in: 8.0.0Fixed in: 8.4.8
Fixcomposer require drupal/core:^8.4.8

References