github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/2018-10-17-5.yaml GHSA-JJX7-8462-W4M4
Drupal Core Insufficient Contextual Links validation leads to Remote Code Execution
Description
The Contextual Links module doesn't sufficiently validate the requested contextual links. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access contextual links".
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
drupal/drupalBrowse Packagist / drupal/drupal | GitHub Advisory | 8.0.0 to < 8.5.8 · Fixed in 8.5.8 | affected |
| 8.6.0 to < 8.6.2 · Fixed in 8.6.2 | affected |
References
3github.com
https://github.com/drupal/drupal drupal.org
https://www.drupal.org/sa-core-2018-006