drupal-core-2019-007

osv_packagist
Description

This security release fixes third-party dependencies included in or required by Drupal core. As described in [TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor](https://typo3.org/security/advisory/typo3-psa-2019-007/): > In order to intercept file invocations like file\_exists or stat on compromised Phar archives the base name has to be determined and checked before allowing to be handled by PHP Phar stream handling. [...] > > The current implementation is vulnerable to path traversal leading to scenarios where the Phar archive to be assessed is not the actual (compromised) file. The known vulnerability in Drupal core requires the "administer themes" permission. However, additional vulnerabilities may exist in contributed or custom modules, so site should still update even if they do not grant this permission.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "affected_versions": ">=7.0 <7.67 || >= 8.0.0 <8.6.16 || >=8.7.0 <8.7.1",
        "source": "https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/core/DRUPAL-CORE-2019-007.json"
      },
      "package": {
        "ecosystem": "Packagist",
        "name": "drupal/core",
        "purl": "pkg:composer/drupal/core"
      },
      "ranges": [
        {
          "database_specific": {
            "constraint": ">= 8.0.0 <8.6.16"
          },
          "events": [
            {
              "introduced": "8.0.0"
            },
            {
              "fixed": "8.6.16"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "database_specific": {
            "constraint": ">=8.7.0 <8.7.1"
          },
          "events": [
            {
              "introduced": "8.7.0"
            },
            {
              "fixed": "8.7.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "8.0.0",
        "8.0.1",
        "8.0.2",
        "8.0.3",
        "8.0.4",
        "8.0.5",
        "8.0.6",
        "8.1.0",
        "8.1.0-beta1",
        "8.1.0-beta2",
        "8.1.0-rc1",
        "8.1.1",
        "8.1.10",
        "8.1.2",
        "8.1.3",
        "8.1.4",
        "8.1.5",
        "8.1.6",
        "8.1.7",
        "8.1.8",
        "8.1.9",
        "8.2.0",
        "8.2.0-beta1",
        "8.2.0-beta2",
        "8.2.0-beta3",
        "8.2.0-rc1",
        "8.2.0-rc2",
        "8.2.1",
        "8.2.2",
        "8.2.3",
        "8.2.4",
        "8.2.5",
        "8.2.6",
        "8.2.7",
        "8.2.8",
        "8.3.0",
        "8.3.0-alpha1",
        "8.3.0-beta1",
        "8.3.0-rc1",
        "8.3.0-rc2",
        "8.3.1",
        "8.3.2",
        "8.3.3",
        "8.3.4",
        "8.3.5",
        "8.3.6",
        "8.3.7",
        "8.3.8",
        "8.3.9",
        "8.4.0",
        "8.4.0-alpha1",
        "8.4.0-beta1",
        "8.4.0-rc1",
        "8.4.0-rc2",
        "8.4.1",
        "8.4.2",
        "8.4.3",
        "8.4.4",
        "8.4.5",
        "8.4.6",
        "8.4.7",
        "8.4.8",
        "8.5.0",
        "8.5.0-alpha1",
        "8.5.0-beta1",
        "8.5.0-rc1",
        "8.5.1",
        "8.5.10",
        "8.5.11",
        "8.5.12",
        "8.5.13",
        "8.5.14",
        "8.5.15",
        "8.5.2",
        "8.5.3",
        "8.5.4",
        "8.5.5",
        "8.5.6",
        "8.5.7",
        "8.5.8",
        "8.5.9",
        "8.6.0",
        "8.6.0-alpha1",
        "8.6.0-beta1",
        "8.6.0-beta2",
        "8.6.0-rc1",
        "8.6.1",
        "8.6.10",
        "8.6.11",
        "8.6.12",
        "8.6.13",
        "8.6.14",
        "8.6.15",
        "8.6.2",
        "8.6.3",
        "8.6.4",
        "8.6.5",
        "8.6.6",
        "8.6.7",
        "8.6.8",
        "8.6.9",
        "8.7.0"
      ]
    }
  ],
  "aliases": [
    "CVE-2019-11831",
    "GHSA-xv7v-rf6g-xwrc"
  ],
  "credits": [
    {
      "contact": [
        "https://www.drupal.org/user/3606561"
      ],
      "name": "Daniel Le Gall"
    }
  ],
  "details": "This security release fixes third-party dependencies included in or required by Drupal core. As described in [TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor](https://typo3.org/security/advisory/typo3-psa-2019-007/):\n\n> In order to intercept file invocations like file\\_exists or stat on compromised Phar archives the base name has to be determined and checked before allowing to be handled by PHP Phar stream handling. [...]\n>\n> The current implementation is vulnerable to path traversal leading to scenarios where the Phar archive to be assessed is not the actual (compromised) file.\n\nThe known vulnerability in Drupal core requires the \"administer themes\" permission. However, additional vulnerabilities may exist in contributed or custom modules, so site should still update even if they do not grant this permission.",
  "id": "DRUPAL-CORE-2019-007",
  "modified": "2026-09-19T19:25:50Z",
  "published": "2019-05-08T16:56:58Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://www.drupal.org/sa-core-2019-007"
    }
  ],
  "schema_version": "1.9.0"
}
View JSON API Download JSON