Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.
The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
Install the latest version:
If you are using Drupal 10.2, update to Drupal 10.2.10.
Drupal 10.3 and above are not affected, nor is Drupal 7.
All versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
This advisory is not covered by Drupal Steward.
Lee Rowlands of the Drupal Security Team
Benji Fisher of the Drupal Security Team
Kim Pepper
Wim Leers
xjm of the Drupal Security Team
Dave Long of the Drupal Security Team
Juraj Nemec of the Drupal Security Team
More Stories
USN-7073-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
USN-7072-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
USN-7071-1: Linux kernel vulnerability
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This...
llvm-test-suite-18.1.8-3.fc40
FEDORA-2024-300397332b Packages in this update: llvm-test-suite-18.1.8-3.fc40 Update description: Remove ClamAV subdirectory because of viruses in input files: These were the...
llvm-test-suite-19.1.0-4.fc41
FEDORA-2024-6d9aba8c3c Packages in this update: llvm-test-suite-19.1.0-4.fc41 Update description: Remove ClamAV subdirectory because of viruses in input files: These were the...
libarchive-3.7.2-7.fc40
FEDORA-2024-80e4603b92 Packages in this update: libarchive-3.7.2-7.fc40 Update description: Fix for CVE-2024-48957 Automatic update for libarchive-3.7.2-6.fc40. Read More