CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
EPSS
Percentile
57.4%
This module enables you to create key|value pairs for use in list fields, webforms etc.
The module includes an import page that runs eval()
on an exported code block (ctools), but the permission for the page does not warn about security concerns of importing raw php code like this (trusted permission).
This vulnerability is mitigated by the fact that an attacker must have a role with the permission “import value sets”.
Drupal core is not affected. If you do not use the contributed Values module, there is nothing you need to do.
Install the latest version:
Also see the Values project page.
twitter.com/drupalsecurity
www.drupal.org/contact
www.drupal.org/project/values
www.drupal.org/security-team
www.drupal.org/security-team/risk-levels
www.drupal.org/security/secure-configuration
www.drupal.org/u/greggles
www.drupal.org/u/mlhess
www.drupal.org/user/1485048
www.drupal.org/user/823702
www.drupal.org/writing-secure-code
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
EPSS
Percentile
57.4%