Arbitrary File Upload Affecting drupal/core package, versions >=8, <8.3.4


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (72nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary File Upload vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-DRUPALCORE-70061
  • published21 Jun 2017
  • disclosed21 Jun 2017
  • creditSamuel Mortenson

Introduced: 21 Jun 2017

CVE-2017-6921  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade drupal/core to version 8.3.4 or higher.

Overview

Affected versions of drupal/core are vulnerable to Arbitrary File Upload.

The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is enabled and allows PATCH requests, and an attacker can get or register a user account on the site with permissions to upload files and to modify the file resource.

CVSS Scores

version 3.1