6 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
8 High
AI Score
Confidence
High
0.007 Low
EPSS
Percentile
81.0%
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details
CPE | Name | Operator | Version |
---|---|---|---|
drupal:drupal | drupal | lt | 7.62 |
drupal:drupal | drupal | lt | 8.5.9 |
drupal:drupal | drupal | lt | 8.6.6 |
[
{
"product": "Drupal core",
"vendor": "Drupal",
"versions": [
{
"lessThan": "7.62",
"status": "affected",
"version": "7.x",
"versionType": "custom"
},
{
"lessThan": "8.6.6. ",
"status": "affected",
"version": "8.6.x",
"versionType": "custom"
},
{
"lessThan": "8.5.9",
"status": "affected",
"version": "8.5.x",
"versionType": "custom"
}
]
}
]
6 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
8 High
AI Score
Confidence
High
0.007 Low
EPSS
Percentile
81.0%