Description:
Drupal released security update to fix the vulnerability in the Workspaces module which are included in the Drupal core. A remote attacker may send specially crafted HTTP requests to exploit the vulnerability if the experimental Workspaces module is enabled.
Affected Systems:
Impact:
A successful attack could lead to security restriction bypass on an affected system.
Recommendation:
The product vendor has released patches to address the issues.
- Drupal 8.7.5
https://www.drupal.org/project/drupal/releases/8.7.5
More Information:
https://www.drupal.org/sa-core-2019-008
https://www.hkcert.org/my_url/en/alert/19071801
https://www.us-cert.gov/ncas/current-activity/2019/07/17/drupal-releases-security-update
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6342