Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 654154 (CVE-2018-7602, CVE-2018-9861)

Summary: <www-apps/drupal-{7.59,8.5.3}: multiple vulnerabilities (CVE-2018-{7602,9861})
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: ~1 [noglsa cve]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2018-04-26 21:54:05 UTC
CVE-2018-9861 (https://nvd.nist.gov/vuln/detail/CVE-2018-9861):
  Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2)
  plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as
  used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products,
  allows remote attackers to inject arbitrary web script through a crafted IMG
  element.

CVE-2018-7602 (https://nvd.nist.gov/vuln/detail/CVE-2018-7602):
  A remote code execution vulnerability exists within multiple subsystems of
  Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple
  attack vectors on a Drupal site, which could result in the site being
  compromised.


CVE-2018-9861: https://www.drupal.org/sa-core-2018-003

CVE-2018-7602: https://www.drupal.org/sa-core-2018-004
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2018-04-26 21:55:59 UTC
Repository is clean, no stable packages, all done.