CVE-2019-6340
Drupal Core Remote Code Execution Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 8.1
- EPSS
- 91.9% 백분위 99.8% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.04.15
- 공개일
- 2019.02.22
CISA KEV에 등록된 실제 악용 확인 취약점
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you...
공급사 Drupal
제품 Core
영향 버전 8.5, 8.6, >= 8.5.0 < 8.5.11, >= 8.6.0 < 8.6.10
수정 버전 8.5.11, 8.6.10
Apply updates per vendor instructions.
조치 기한: 2022.04.15CVSS 벡터 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-502
KEV 등록일 2022.03.25
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2019-6340
EPSS 데이터 기준일 2026.06.27