{"id":"GHSA-52jr-x6h6-xj6g","summary":"Drupal core vulnerable to improper error handling","details":"Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.\n\nThe issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.","aliases":["BIT-drupal-2024-11942","CVE-2024-11942","DRUPAL-CORE-2024-002"],"modified":"2025-12-10T23:40:59.635498Z","published":"2024-12-05T15:31:02Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-12-05T19:58:23Z","nvd_published_at":"2024-12-05T15:15:08Z","cwe_ids":["CWE-390"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11942"},{"type":"PACKAGE","url":"https://github.com/drupal/core"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2024-002"}],"affected":[{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.2.10"}]}],"versions":["10.0.0","10.0.1","10.0.10","10.0.11","10.0.2","10.0.3","10.0.4","10.0.5","10.0.6","10.0.7","10.0.8","10.0.9","10.1.0","10.1.0-alpha1","10.1.0-beta1","10.1.0-rc1","10.1.1","10.1.2","10.1.3","10.1.4","10.1.5","10.1.6","10.1.7","10.1.8","10.2.0","10.2.0-alpha1","10.2.0-beta1","10.2.0-rc1","10.2.1","10.2.2","10.2.3","10.2.4","10.2.5","10.2.6","10.2.7","10.2.8","10.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-52jr-x6h6-xj6g/GHSA-52jr-x6h6-xj6g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}