Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.

This vulnerability affects the following application versions:

  • Drupal 10.0.0
  • Drupal 10.0.1
  • Drupal 10.0.2
  • Drupal 10.0.3
  • Drupal 10.0.4
  • Drupal 10.0.5
  • Drupal 10.0.6
  • Drupal 10.0.7
  • Drupal 10.0.8
  • Drupal 10.0.9
  • Drupal 10.0.10
  • Drupal 10.0.11
  • Drupal 10.1.0
  • Drupal 10.1.1
  • Drupal 10.1.2
  • Drupal 10.1.3
  • Drupal 10.1.4
  • Drupal 10.1.5
  • Drupal 10.1.6
  • Drupal 10.1.7
  • Drupal 10.1.8
  • Drupal 10.2.0
  • Drupal 10.2.1
  • Drupal 10.2.2
  • Drupal 10.2.3
  • Drupal 10.2.4
  • Drupal 10.2.5
  • Drupal 10.2.6
  • Drupal 10.2.7
  • Drupal 10.2.8
  • Drupal 10.2.9

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *