VDB
Sign up
—

DRUPAL-CORE-2020-005

Quick fix

DRUPAL-CORE-2020-005 — drupal/core: upgrade to the fixed version with the command below.

composer require drupal/core:^8.8.8

Details

Drupal 8 and 9 have a remote code execution vulnerability under certain circumstances.

An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability.

Windows servers are most likely to be affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/drupal/core
Introduced in: 8.0.0Fixed in: 8.8.8
Fixcomposer require drupal/core:^8.8.8

References