Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6381


A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies aren't normal installed. You might be vulnerable to this if you are running a version of Drupal before 8.2.2. To be sure you aren't vulnerable, you can remove the <siteroot>/vendor/phpunit directory from your production deployments


Published

2017-03-16T14:59:00.300

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-829

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.0 Yes
Application drupal drupal 8.0.1 Yes
Application drupal drupal 8.0.2 Yes
Application drupal drupal 8.0.3 Yes
Application drupal drupal 8.0.4 Yes
Application drupal drupal 8.0.5 Yes
Application drupal drupal 8.0.6 Yes
Application drupal drupal 8.1.0 Yes
Application drupal drupal 8.1.0 Yes
Application drupal drupal 8.1.0 Yes
Application drupal drupal 8.1.0 Yes
Application drupal drupal 8.1.1 Yes
Application drupal drupal 8.1.2 Yes
Application drupal drupal 8.1.3 Yes
Application drupal drupal 8.1.4 Yes
Application drupal drupal 8.1.5 Yes
Application drupal drupal 8.1.6 Yes
Application drupal drupal 8.1.7 Yes
Application drupal drupal 8.1.8 Yes
Application drupal drupal 8.1.9 Yes
Application drupal drupal 8.1.10 Yes
Application drupal drupal 8.2.0 Yes
Application drupal drupal 8.2.0 Yes
Application drupal drupal 8.2.0 Yes
Application drupal drupal 8.2.0 Yes
Application drupal drupal 8.2.0 Yes
Application drupal drupal 8.2.0 Yes
Application drupal drupal 8.2.1 Yes

References