DNA View

⚠️ CISA Known Exploited Vulnerability

Active Threat

This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.

CVE-2019-6340

High CISA KEV
Low Medium High Critical
8.1
CVSS Score
Published: Feb 21, 2019
Last Modified: Nov 07, 2025

Vulnerability Description

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

21 configuration(s) from 1 vendor(s)

drupal
Version:
8.5.7
CPE:
cpe:2.3:a:drupal:drupal:8.5.7:*:*:*:*:*:*:*
drupal
Version:
8.5.0
CPE:
cpe:2.3:a:drupal:drupal:8.5.0:-:*:*:*:*:*:*
drupal
Version:
8.6.7
CPE:
cpe:2.3:a:drupal:drupal:8.6.7:*:*:*:*:*:*:*
drupal
Version:
8.6.2
CPE:
cpe:2.3:a:drupal:drupal:8.6.2:*:*:*:*:*:*:*
drupal
Version:
8.6.3
CPE:
cpe:2.3:a:drupal:drupal:8.6.3:*:*:*:*:*:*:*
drupal
Version:
8.5.3
CPE:
cpe:2.3:a:drupal:drupal:8.5.3:*:*:*:*:*:*:*
drupal
Version:
8.5.8
CPE:
cpe:2.3:a:drupal:drupal:8.5.8:*:*:*:*:*:*:*
drupal
Version:
8.6.6
CPE:
cpe:2.3:a:drupal:drupal:8.6.6:*:*:*:*:*:*:*
drupal
Version:
8.6.5
CPE:
cpe:2.3:a:drupal:drupal:8.6.5:*:*:*:*:*:*:*
drupal
Version:
8.6.0
CPE:
cpe:2.3:a:drupal:drupal:8.6.0:-:*:*:*:*:*:*
drupal
Version:
8.6.8
CPE:
cpe:2.3:a:drupal:drupal:8.6.8:*:*:*:*:*:*:*
drupal
Version:
8.5.6
CPE:
cpe:2.3:a:drupal:drupal:8.5.6:*:*:*:*:*:*:*
drupal
Version:
8.6.9
CPE:
cpe:2.3:a:drupal:drupal:8.6.9:*:*:*:*:*:*:*
drupal
Version:
8.5.2
CPE:
cpe:2.3:a:drupal:drupal:8.5.2:*:*:*:*:*:*:*
drupal
Version:
8.5.9
CPE:
cpe:2.3:a:drupal:drupal:8.5.9:*:*:*:*:*:*:*
drupal
Version:
8.5.4
CPE:
cpe:2.3:a:drupal:drupal:8.5.4:*:*:*:*:*:*:*
drupal
Version:
8.5.5
CPE:
cpe:2.3:a:drupal:drupal:8.5.5:*:*:*:*:*:*:*
drupal
Version:
8.6.1
CPE:
cpe:2.3:a:drupal:drupal:8.6.1:*:*:*:*:*:*:*
drupal
Version:
8.5.1
CPE:
cpe:2.3:a:drupal:drupal:8.5.1:*:*:*:*:*:*:*
drupal
Version:
8.6.4
CPE:
cpe:2.3:a:drupal:drupal:8.6.4:*:*:*:*:*:*:*
drupal
Version:
8.5.10
CPE:
cpe:2.3:a:drupal:drupal:8.5.10:*:*:*:*:*:*:*
This vulnerability affects 21 software configuration(s). Ensure you patch all affected systems.

Severity Details

8.1
out of 10.0
High

CISA KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog

Weakness Type (CWE)

CWE-502 Top 25 #15

Deserialization of Untrusted Data

Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Exploit Likelihood
Medium
Typical Severity
Medium
OWASP Top 10
A08:2021-Software/Data Integrity Failures
Abstraction Level
Base

Key Information

Published Date
February 21, 2019