Loading HuntDB...

GHSA-v8wr-r69p-mmwx

GitHub Security Advisory

Unrestricted Upload of File with Dangerous Type in Drupal core

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

Affected Packages

Packagist drupal/core
Affected versions: 8.0.0 (fixed in 8.9.19)
Packagist drupal/core
Affected versions: 9.1.0 (fixed in 9.1.13)
Packagist drupal/core
Affected versions: 9.2.0 (fixed in 9.2.6)

Related CVEs

Key Information

GHSA ID
GHSA-v8wr-r69p-mmwx
Published
February 12, 2022 12:00 AM
Last Modified
February 23, 2022 7:14 PM
CVSS Score
9.0 /10
Primary Ecosystem
Packagist
Primary Package
drupal/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.