VulnerabilityAnalyzed
CVE-2018-7600
Drupal Core Remote Code Execution Vulnerability
KEVCRITICAL 9.8EPSS 100.0%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.99% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-20
- Affected
- drupal/drupal · debian/debian linux
- Source
- mlhess@drupal.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-7600
References
- http://www.securityfocus.com/bid/103534Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040598Broken Link, Third Party Advisory, VDB Entry
- https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/Broken Link, Third Party Advisory
- https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714Third Party Advisory
- https://github.com/a2u/CVE-2018-7600Third Party Advisory
- https://github.com/g0rx/CVE-2018-7600-Drupal-RCEPatch, Third Party Advisory
- https://greysec.net/showthread.php?tid=2912&pid=10561Broken Link, Issue Tracking, Third Party Advisory
- https://groups.drupal.org/security/faq-2018-002Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00028.htmlThird Party Advisory
- https://research.checkpoint.com/uncovering-drupalgeddon-2/Exploit, Third Party Advisory
- https://twitter.com/RicterZ/status/979567469726613504Broken Link, Third Party Advisory
- https://twitter.com/RicterZ/status/984495201354854401Broken Link, Third Party Advisory
- https://twitter.com/arancaytar/status/979090719003627521Third Party Advisory
- https://www.debian.org/security/2018/dsa-4156Third Party Advisory
- https://www.drupal.org/sa-core-2018-002Vendor Advisory
- https://www.exploit-db.com/exploits/44448/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44449/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44482/Exploit, Third Party Advisory, VDB Entry
- https://www.synology.com/support/security/Synology_SA_18_17Third Party Advisory
- https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-knowThird Party Advisory
- http://www.securityfocus.com/bid/103534Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040598Broken Link, Third Party Advisory, VDB Entry
- https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/Broken Link, Third Party Advisory
- https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714Third Party Advisory
- https://github.com/a2u/CVE-2018-7600Third Party Advisory
- https://github.com/g0rx/CVE-2018-7600-Drupal-RCEPatch, Third Party Advisory
- https://greysec.net/showthread.php?tid=2912&pid=10561Broken Link, Issue Tracking, Third Party Advisory
- https://groups.drupal.org/security/faq-2018-002Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00028.htmlThird Party Advisory
- https://research.checkpoint.com/uncovering-drupalgeddon-2/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.