VDB
Sign up
—

DRUPAL-CORE-2019-003

Quick fix

DRUPAL-CORE-2019-003 — drupal/core: upgrade to the fixed version with the command below.

composer require drupal/core:^8.5.11

Details

Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

A site is only affected by this if one of the following conditions is met:

* The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows **GET**, PATCH or POST requests, or * the site has another web services module enabled, like [JSON:API](https://www.drupal.org/project/jsonapi) in Drupal 8, or [Services](https://www.drupal.org/project/services) or [RESTful Web Services](https://www.drupal.org/project/restws) in Drupal 7.

(*Note: The Drupal 7 Services module itself does not require an update at this time, but you should still apply other contributed updates associated with this advisory if Services is in use.*)

Updates -------

* **2019-02-22**: Updated risk score given new information; see [PSA-2019-02-22](https://www.drupal.org/psa-2019-02-22). The security risk score has been updated to 23/25 as there are now known exploits in the wild. In addition, any enabled REST resource end-point, **even if it only accepts GET requests**, is also vulnerable. Note this does not include REST exports from Views module.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/drupal/core
Introduced in: 8.0.0Fixed in: 8.5.11
Fixcomposer require drupal/core:^8.5.11

References