#VU17233 Security restrictions bypass in Drupal - CVE-2019-6338
Published: January 28, 2019
Drupal
Drupal
Description
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the system.
The vulnerability exists in the Drupal core PEAR Archive_Tar library due to an unsafe object deserialization condition. A remote attacker can submit a specially crafted tar file to bypass security restrictions on the system and conduct further attacks.