{"id":"GHSA-7fh9-933g-885p","summary":"Drupal Core Remote Code Execution Vulnerability","details":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.","aliases":["CVE-2018-7600","DRUPAL-CORE-2018-002"],"modified":"2025-12-10T23:41:01.770409Z","published":"2022-05-14T01:29:45Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-04-23T22:36:48Z","nvd_published_at":"2018-03-29T07:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7600"},{"type":"WEB","url":"https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know"},{"type":"WEB","url":"https://www.synology.com/support/security/Synology_SA_18_17"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/44482"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/44449"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/44448"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2018-002"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4156"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600"},{"type":"WEB","url":"https://twitter.com/arancaytar/status/979090719003627521"},{"type":"WEB","url":"https://twitter.com/RicterZ/status/984495201354854401"},{"type":"WEB","url":"https://twitter.com/RicterZ/status/979567469726613504"},{"type":"WEB","url":"https://research.checkpoint.com/uncovering-drupalgeddon-2"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html"},{"type":"WEB","url":"https://groups.drupal.org/security/faq-2018-002"},{"type":"WEB","url":"https://greysec.net/showthread.php?tid=2912&pid=10561"},{"type":"WEB","url":"https://github.com/g0rx/CVE-2018-7600-Drupal-RCE"},{"type":"PACKAGE","url":"https://github.com/drupal/core"},{"type":"WEB","url":"https://github.com/a2u/CVE-2018-7600"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2018-7600.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2018-7600.yaml"},{"type":"WEB","url":"https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714"},{"type":"WEB","url":"https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600"},{"type":"WEB","url":"http://www.securityfocus.com/bid/103534"},{"type":"WEB","url":"http://www.securitytracker.com/id/1040598"}],"affected":[{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0"},{"fixed":"7.58"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}},{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0"},{"fixed":"8.3.9"}]}],"versions":["8.0.0","8.0.0-beta10","8.0.0-beta11","8.0.0-beta12","8.0.0-beta13","8.0.0-beta14","8.0.0-beta15","8.0.0-beta16","8.0.0-beta6","8.0.0-beta7","8.0.0-beta8","8.0.0-beta9","8.0.0-rc1","8.0.0-rc2","8.0.0-rc3","8.0.0-rc4","8.0.1","8.0.2","8.0.3","8.0.4","8.0.5","8.0.6","8.1.0","8.1.0-beta1","8.1.0-beta2","8.1.0-rc1","8.1.1","8.1.10","8.1.2","8.1.3","8.1.4","8.1.5","8.1.6","8.1.7","8.1.8","8.1.9","8.2.0","8.2.0-beta1","8.2.0-beta2","8.2.0-beta3","8.2.0-rc1","8.2.0-rc2","8.2.1","8.2.2","8.2.3","8.2.4","8.2.5","8.2.6","8.2.7","8.2.8","8.3.0","8.3.0-alpha1","8.3.0-beta1","8.3.0-rc1","8.3.0-rc2","8.3.1","8.3.2","8.3.3","8.3.4","8.3.5","8.3.6","8.3.7","8.3.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}},{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.4.0"},{"fixed":"8.4.6"}]}],"versions":["8.4.0","8.4.1","8.4.2","8.4.3","8.4.4","8.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}},{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.0"},{"fixed":"8.5.1"}]}],"versions":["8.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}},{"package":{"name":"drupal/drupal","ecosystem":"Packagist","purl":"pkg:composer/drupal/drupal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0"},{"fixed":"7.58"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}},{"package":{"name":"drupal/drupal","ecosystem":"Packagist","purl":"pkg:composer/drupal/drupal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0"},{"fixed":"8.3.9"}]}],"versions":["8.0.0","8.0.0-alpha14","8.0.0-alpha15","8.0.0-beta1","8.0.0-beta10","8.0.0-beta11","8.0.0-beta12","8.0.0-beta13","8.0.0-beta14","8.0.0-beta15","8.0.0-beta16","8.0.0-beta2","8.0.0-beta3","8.0.0-beta4","8.0.0-beta5","8.0.0-beta6","8.0.0-beta7","8.0.0-beta9","8.0.0-rc1","8.0.0-rc2","8.0.0-rc3","8.0.0-rc4","8.0.1","8.0.2","8.0.3","8.0.4","8.0.5","8.0.6","8.1.0","8.1.0-beta1","8.1.0-beta2","8.1.0-rc1","8.1.1","8.1.10","8.1.2","8.1.3","8.1.4","8.1.5","8.1.6","8.1.7","8.1.8","8.1.9","8.2.0","8.2.0-beta1","8.2.0-beta2","8.2.0-beta3","8.2.0-rc1","8.2.0-rc2","8.2.1","8.2.2","8.2.3","8.2.4","8.2.5","8.2.6","8.2.7","8.2.8","8.3.0","8.3.0-alpha1","8.3.0-beta1","8.3.0-rc1","8.3.0-rc2","8.3.1","8.3.2","8.3.3","8.3.4","8.3.5","8.3.6","8.3.7","8.3.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}},{"package":{"name":"drupal/drupal","ecosystem":"Packagist","purl":"pkg:composer/drupal/drupal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.4"},{"fixed":"8.4.6"}]}],"versions":["8.4.0","8.4.0-alpha1","8.4.0-beta1","8.4.0-rc1","8.4.0-rc2","8.4.1","8.4.2","8.4.3","8.4.4","8.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}},{"package":{"name":"drupal/drupal","ecosystem":"Packagist","purl":"pkg:composer/drupal/drupal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5"},{"fixed":"8.5.1"}]}],"versions":["8.5.0","8.5.0-alpha1","8.5.0-beta1","8.5.0-rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H"}]}