Bug 1572099 (CVE-2018-7602)

Summary: CVE-2018-7602 drupal: Remote code execution vulnerability SA-CORE-2018-004
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: amaris, ccoleman, dedgar, dmcphers, jgoulding, jsmith.fedora, peter, shawn, stickster
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: drupal 7.59, drupal 8.4.8, drupal 8.5.3 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-08-13 06:54:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1572100, 1572101, 1572102, 1572373    
Bug Blocks: 1572103    

Description Adam Mariš 2018-04-26 08:03:04 UTC
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised.

Upstream patches:

Drupal 8.x: https://cgit.drupalcode.org/drupal/rawdiff/?h=8.5.x&id=bb6d396609600d1169da29456ba3db59abae4b7e
Drupal 7.x: https://cgit.drupalcode.org/drupal/rawdiff/?h=7.x&id=080daa38f265ea28444c540832509a48861587d0

External References:

https://www.drupal.org/sa-core-2018-004

Comment 1 Adam Mariš 2018-04-26 08:03:32 UTC
Created drupal8 tracking bugs for this issue:

Affects: fedora-all [bug 1572101]


Created drupal7 tracking bugs for this issue:

Affects: fedora-all [bug 1572100]
Affects: epel-all [bug 1572102]

Comment 3 Shawn Iwinski 2018-08-11 04:39:07 UTC
All dependent bugs are closed.  Please close this one out.

Comment 4 Adam Mariš 2018-08-13 06:54:43 UTC
(In reply to Shawn Iwinski from comment #3)
> All dependent bugs are closed.  Please close this one out.

OK, thanks!