Administrators must create a new update to fix a remote code execution vulnerability. The Drupal content management system platform has issued an advisory for a critical remote code execution (RCE) flaw in the Drupal core.
The bug (CVE-2019-6340) results from the fact that “some field types do not properly sanitize data from non-form sources,” according to a Drupal advisory on Wednesday.
Insufficient validation of incoming data can lead to various types of code injection, opening the door to cross-site scripting, website or server hacking, and in some cases, can be used to steal user credentials or plant malware. Drupal said that the flaw in question can lead to arbitrary PHP code execution, in some cases.
CMS vulnerabilities are sought after by hackers, as they can provide access to millions of vulnerable sites at once. Drupal, for its part, provides a back-end framework for at least 4.6% of all websites worldwide – from personal blogs to corporate, political and government sites. While that may sound small, it is the third most popular web platform in the world after WordPress and Joomla. Drupal powers an estimated 73.6 million of the 1.6 billion websites online in the world.
Those using Drupal 8.6.x can upgrade to Drupal 8.6.10 to fix the bug. And those using Drupal 8.5.x or earlier can upgrade to Drupal 8.5.11. The Drupal 7 Services module is not affected, but administrators should continue to apply other updates, the team said.
Affected projects include 0Auth 2.0, Entity Registration, Font Awesome Icons, JSON: API, and RESTful Web Services, so updates are needed for these as well.
A site is only affected by the bug if it has the Drupal 8 core RESTful Web Services module enabled and allows PATCH or POST requests, or if it has another web-services module enabled, such as JSON: API in Drupal 8 or Services or RESTful Web Services in Drupal 7.
To mitigate the error before applying the updates, administrators should disable all web services modules or configure the servers to not allow PUT/PATCH/POST requests.
