CVE-2019-6340

Drupal core - Highly critical - Remote Code Execution

Basic Information

CVE State
PUBLISHED
Reserved Date
January 15, 2019
Published Date
February 21, 2019
Last Updated
February 07, 2025
Vendor
Drupal
Product
Drupal Core
Description
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

CVSS Scores

CVSS v3.1

8.1 - HIGH

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-03-25 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2021-05-01 15:00:34 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-03-25 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

drupal_restws_unserialize

Type: metasploit • Created: Unknown

Metasploit module for CVE-2019-6340

nobodyatall648/CVE-2019-6340

Type: github • Created: 2021-05-01 15:00:34 UTC • Stars: 0

Drupal Drupal 8.6.x RCE Exploit

jas502n/CVE-2019-6340

Type: github • Created: 2019-05-27 19:06:14 UTC • Stars: 70

Drupal8's REST RCE, SA-CORE-2019-003, CVE-2019-6340

oways/CVE-2019-6340

Type: github • Created: 2019-02-25 07:47:16 UTC • Stars: 12

CVE-2019-6340 POC Drupal rce

DevDungeon/CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass

Type: github • Created: 2019-02-25 03:38:47 UTC • Stars: 2

CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples

knqyf263/CVE-2019-6340

Type: github • Created: 2019-02-23 13:28:58 UTC • Stars: 43

Environment for CVE-2019-6340 (Drupal)