DRUPAL-CORE-2019-003
Quick fix
DRUPAL-CORE-2019-003 — drupal/core: upgrade to the fixed version with the command below.
composer require drupal/core:^8.5.11Details
Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
A site is only affected by this if one of the following conditions is met:
* The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows **GET**, PATCH or POST requests, or * the site has another web services module enabled, like [JSON:API](https://www.drupal.org/project/jsonapi) in Drupal 8, or [Services](https://www.drupal.org/project/services) or [RESTful Web Services](https://www.drupal.org/project/restws) in Drupal 7.
(*Note: The Drupal 7 Services module itself does not require an update at this time, but you should still apply other contributed updates associated with this advisory if Services is in use.*)
Updates -------
* **2019-02-22**: Updated risk score given new information; see [PSA-2019-02-22](https://www.drupal.org/psa-2019-02-22). The security risk score has been updated to 23/25 as there are now known exploits in the wild. In addition, any enabled REST resource end-point, **even if it only accepts GET requests**, is also vulnerable. Note this does not include REST exports from Views module.
Are you affected?
Enter the version of the package you're using.