Drupal core½Ó¼ûȨÏÞ½ÚÔìʧЧ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-6342 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Drupal 8.7.4


·ì϶¸ÅÊö


Drupal coreÊÇDrupalÉçÇøËùÊØ»¤µÄÒ»Ì×ÓÃPHP˵»°¿ª·¢µÄÃâ·Ñ¡¢¿ªÔ´µÄÄÚÈÝÖÎÀíϵͳ¡£


ÔÚDrupal 8.7.4°æ±¾ÖÐ £¬µ±´¦ÓÚ³¢ÊÔÐÔµÄÖ°ÄÜ Workspaces (¹¤×÷ÇøÄ  £¿é) ¿ªÆôµÄʱ³½ £¬²¿ÃÅõè¾¶½«²»Êܵ½½Ó¼ûȨÏÞÖÎÀí½ÚÔìµÄÏÞ¶È £¬Äܹ»±»ËÁÒâ½Ó¼û¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶ £¬½«Drupal¸üе½8.7.5°æ±¾£ºhttps://www.drupal.org/download£»


»º½â´ëÊ©£º½ûÓà Workspaces Ä  £¿é¡£


²Î¿¼Á´½Ó


https://www.drupal.org/sa-core-2019-008