CVE-2018-7600
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Drupal Core Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-20
מוצרים מושפעים
drupal: drupal; debian: debian linux
קישורים
- https://groups.drupal.org/security/faq-2018-002 Vendor Advisory
- https://www.drupal.org/sa-core-2018-002 Vendor Advisory
- https://groups.drupal.org/security/faq-2018-002 Vendor Advisory
- https://www.drupal.org/sa-core-2018-002 Vendor Advisory
- https://github.com/g0rx/CVE-2018-7600-Drupal-RCE PatchThird Party Advisory
- https://github.com/g0rx/CVE-2018-7600-Drupal-RCE PatchThird Party Advisory
- https://research.checkpoint.com/uncovering-drupalgeddon-2/ ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/44448/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44449/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44482/ ExploitThird Party AdvisoryVDB Entry