Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 654154 (CVE-2018-7602, CVE-2018-9861) - <www-apps/drupal-{7.59,8.5.3}: multiple vulnerabilities (CVE-2018-{7602,9861})
Summary: <www-apps/drupal-{7.59,8.5.3}: multiple vulnerabilities (CVE-2018-{7602,9861})
Status: RESOLVED FIXED
Alias: CVE-2018-7602, CVE-2018-9861
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-04-26 21:54 UTC by GLSAMaker/CVETool Bot
Modified: 2018-04-26 21:55 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2018-04-26 21:54:05 UTC
CVE-2018-9861 (https://nvd.nist.gov/vuln/detail/CVE-2018-9861):
  Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2)
  plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as
  used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products,
  allows remote attackers to inject arbitrary web script through a crafted IMG
  element.

CVE-2018-7602 (https://nvd.nist.gov/vuln/detail/CVE-2018-7602):
  A remote code execution vulnerability exists within multiple subsystems of
  Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple
  attack vectors on a Drupal site, which could result in the site being
  compromised.


CVE-2018-9861: https://www.drupal.org/sa-core-2018-003

CVE-2018-7602: https://www.drupal.org/sa-core-2018-004
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2018-04-26 21:55:59 UTC
Repository is clean, no stable packages, all done.