VYPR

Bitnami package

drupal

pkg:bitnami/drupal

Vulnerabilities (72)

  • CVE-2020-13667MedMay 17, 2021
    affected >= 8.8.0, < 8.8.10fixed 8.8.10

    Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker might be a

  • CVE-2020-13665CriMay 5, 2021
    affected >= 8.8.0, < 8.8.8fixed 8.8.8

    Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior

  • CVE-2020-13664HigMay 5, 2021
    affected >= 8.8.0, < 8.8.8fixed 8.8.8

    Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker c

  • CVE-2020-13662MedMay 5, 2021
    affected >= 7.0.0, < 7.70.1fixed 7.70.1

    Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.

  • CVE-2020-13666MedMay 5, 2021
    affected >= 7.0.0, < 7.73.0fixed 7.73.0

    Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versions prior to 7.73; 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior

  • CVE-2020-36193HigKEVJan 18, 2021
    affected >= 7.0.0, < 7.78.0fixed 7.78.0

    Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

  • CVE-2020-13671HigKEVNov 20, 2020
    affected >= 7.0.0, < 7.74.0fixed 7.74.0

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 ver

  • CVE-2020-28949HigKEVNov 19, 2020
    affected >= 7.0.0, < 7.75.0fixed 7.75.0

    Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

  • CVE-2020-28948HigNov 19, 2020
    affected >= 7.0.0, < 7.75.0fixed 7.75.0

    Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

  • CVE-2020-11022MedApr 29, 2020
    affected >= 7.0.0, < 7.70.0fixed 7.70.0

    In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

  • CVE-2020-11023MedKEVApr 29, 2020
    affected >= 7.0.0, < 7.70.0fixed 7.70.0

    In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This pro

  • CVE-2020-9281MedMar 7, 2020
    affected >= 8.7.0, < 8.7.12fixed 8.7.12

    A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

Page 4 of 4