tt9133github / ForTest2

0 stars 0 forks source link

CVE-2020-13688 (Medium) detected in drupal/core-8.3.6 #391

Open mend-bolt-for-github[bot] opened 8 months ago

mend-bolt-for-github[bot] commented 8 months ago

CVE-2020-13688 - Medium Severity Vulnerability

Vulnerable Library - drupal/core-8.3.6

Subtree split of drupal's /core directory

Dependency Hierarchy: - :x: **drupal/core-8.3.6** (Vulnerable Library)

Found in HEAD commit: 27e1f740a162e55490d9ca929f243afbaa92476c

Found in base branch: master

Vulnerability Details

Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

Publish Date: 2021-06-11

URL: CVE-2020-13688

CVSS 3 Score Details (6.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.drupal.org/sa-core-2020-009

Release Date: 2021-06-11

Fix Resolution: 8.8.10, 8.9.6, 9.0.6


Step up your Open Source Security Game with Mend here