Back
CVE-2019-6339
CRITICAL
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.
Published: Jan 22, 2019
Modified: Jun 17, 2026
CWE-20
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| drupal | drupal | * ≥ 7.0 < 7.62 |
| drupal | drupal | * ≥ 8.5.0 < 8.5.9 |
| drupal | drupal | * ≥ 8.6.0 < 8.6.6 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
GitHub Security Advisory GHSA-8cw5-rv98-5c46
Arbitrary PHP code execution in Drupal
composer
drupal/drupal
>= 7.0.0, < 7.62.0
Fixed: 7.62.0
composer
drupal/drupal
>= 8.0.0, < 8.5.9
Fixed: 8.5.9
composer
drupal/drupal
>= 8.6.0, < 8.6.6
Fixed: 8.6.6
composer
drupal/core
>= 7.0.0, < 7.62.0
Fixed: 7.62.0
composer
drupal/core
>= 8.0.0, < 8.5.9
Fixed: 8.5.9
composer
drupal/core
>= 8.6.0, < 8.6.6
Fixed: 8.6.6
References (6)
- https://lists.debian.org/debian-lts-announce/2019/02/msg00004.html Third Party Advisory
- https://www.debian.org/security/2019/dsa-4370 Third Party Advisory
- https://www.drupal.org/sa-core-2019-002 Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00004.html Third Party Advisory
- https://www.debian.org/security/2019/dsa-4370 Third Party Advisory
- https://www.drupal.org/sa-core-2019-002 Patch, Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
33.23%
Top 2% most likely to be exploited
Threat Score
49.2 / 100
Data Sources
NVD
EPSS
GitHub