{"id":"GHSA-jjx7-8462-w4m4","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jjx7-8462-w4m4","summary":"Drupal Core Insufficient Contextual Links validation leads to Remote Code Execution","details":"The Contextual Links module doesn't sufficiently validate the requested contextual links.\nThis vulnerability is mitigated by the fact that an attacker must have a role with the permission \"access contextual links\".","published":"2024-05-15T20:57:20Z","modified":"2024-11-29T05:45:01.013296Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.5.8"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.6.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/2018-10-17-5.yaml"},{"type":"PACKAGE","url":"https://github.com/drupal/drupal"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2018-006"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:45:01.013296Z"}}