CVE-2020-13671
Drupal core Un-restricted Upload of File
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 18 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 35.35% probability · 98th percentile
- CISA KEV
- Listed 18 January 2022 · due 18 July 2022
- Weakness
- CWE-434
- Affected
- drupal/drupal · fedoraproject/fedora
- Source
- mlhess@drupal.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-13671
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5KSFM672XW3X6BR7TVKRD63SLZGKK437/Mailing List, Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWM4CTMEGAC4I2CHYNJVSROY4CVXVEUT/Mailing List, Release Notes
- https://www.drupal.org/sa-core-2020-012Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5KSFM672XW3X6BR7TVKRD63SLZGKK437/Mailing List, Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWM4CTMEGAC4I2CHYNJVSROY4CVXVEUT/Mailing List, Release Notes
- https://www.drupal.org/sa-core-2020-012Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-13671US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.