SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2020-13671

Drupal core Un-restricted Upload of File

KEVHIGH 8.8EPSS 35.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 18 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
35.35% probability · 98th percentile
CISA KEV
Listed 18 January 2022 · due 18 July 2022
Weakness
CWE-434
Affected
drupal/drupal · fedoraproject/fedora
Source
mlhess@drupal.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-13671

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.