Vulnerability Intelligence Report
Drupal core - Critical - Access bypass - SA-CORE-2019-008
CVE-2019-6342
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:1.60%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Drupal | Drupal Core | Drupal 8 8.7.4 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.598%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Drupal.org · Vendor · USA |
| Reserved | 2019-01-15T00:00:00 |
| Published | 2020-05-28T20:59:46 |
| Last Updated | 2024-08-04T20:23:20 |
Community Chatter & Buzz