Code injection in Drupal - CVE-2018-7602

 

Code injection in Drupal - CVE-2018-7602

Published: April 25, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU12182
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7602
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable website.

The vulnerability exists due to improper input validation when processing HTTP requests. A remote unauthenticated attacker can send a specially crafted HTTP request to vulnerable website and compromise it.

Successful exploitation of the vulnerability may allow an attacker to gain full access to vulnerable website.

Note: the vendor updated the original advisory stating that this vulnerability is being exploited in the wild.

Affected software

Drupal
Arch Linux
Debian Linux
Fedora
drupal7 (Debian package)
drupal7 (Alpine package)
drupal7
drupal8

How to mitigate CVE-2018-7602

Update to version 7.59, 8.4.8 or 8.5.3.

drupal7 (Debian package) - update to 7.52-2+deb9u5
drupal7 (Alpine package) - update to 7.59-r0
drupal7 - addressed in versions 7.59-1.el6, 7.59-1.el7, 7.59-1.fc26, 7.59-1.fc27, 7.59-1.fc28
drupal8 - addressed in versions 8.4.8-1.fc27, 8.4.8-1.fc28

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins