Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.
The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
Install the latest version:
If you are using Drupal 10.2, update to Drupal 10.2.10.
Drupal 10.3 and above are not affected, nor is Drupal 7.
All versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
This advisory is not covered by Drupal Steward.
Lee Rowlands of the Drupal Security Team
Benji Fisher of the Drupal Security Team
Kim Pepper
Wim Leers
xjm of the Drupal Security Team
Dave Long of the Drupal Security Team
Juraj Nemec of the Drupal Security Team
More Stories
llvm-test-suite-18.1.8-3.fc40
FEDORA-2024-300397332b Packages in this update: llvm-test-suite-18.1.8-3.fc40 Update description: Remove ClamAV subdirectory because of viruses in input files: These were the...
llvm-test-suite-19.1.0-4.fc41
FEDORA-2024-6d9aba8c3c Packages in this update: llvm-test-suite-19.1.0-4.fc41 Update description: Remove ClamAV subdirectory because of viruses in input files: These were the...
libarchive-3.7.2-7.fc40
FEDORA-2024-80e4603b92 Packages in this update: libarchive-3.7.2-7.fc40 Update description: Fix for CVE-2024-48957 Automatic update for libarchive-3.7.2-6.fc40. Read More
USN-7048-2: Vim vulnerability
USN-7048-1 fixed a vulnerability in Vim. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: Suyue...
USN-7070-1: libarchive vulnerabilities
It was discovered that libarchive mishandled certain memory checks, which could result in a NULL pointer dereference. An attacker could...
USN-7038-2: APR vulnerability
USN-7038-1 fixed a vulnerability in Apache Portable Runtime (APR) library. This update provides the corresponding update for Ubuntu 14.04 LTS....