VDB
CVE-2019-6339
CVE-2019-6339
PUBLISHED
CVSS 9.800000190734863 CRITICAL
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.
EPSS 33.23% · 98.2th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
33.23%
98.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | drupal7 | 0, 7.38-1, 7.41-1 |
| Ubuntu:Pro:14.04:LTS | drupal7 | 7.26-1ubuntu0.1+esm3, 0, * |
Timeline
- Jan 16, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Aug 21, 2022 CVE Updated
- Jan 16, 2024 EPSS Score
- Jul 24, 2024 EPSS Score
- Dec 2, 2024 EPSS Score
- Jan 1, 2025 EPSS Score
- Mar 18, 2025 EPSS Score
- Mar 27, 2025 EPSS Score
- Mar 28, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-6339 third-party-advisory
- https://www.drupal.org/sa-core-2019-002 third-party-advisory
- https://www.debian.org/security/2019/dsa-4370 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-6339 third-party-advisory