UNKNOWNCVE-2024-11942
Drupal core vulnerable to improper error handling
Platform
drupal
Component
drupal
Fixed in
10.2.10
Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site. The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
How to fix
Actualice Drupal Core a la versión 10.2.10 o superior. Esta actualización corrige la vulnerabilidad de manejo de errores. Realice una copia de seguridad de su sitio web antes de actualizar.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free