Description
*Updated 2022-07-20 19:45 UTC to indicate that this only affects Apache web servers.* Drupal core sanitizes filenames with dangerous extensions upon upload (reference: [SA-CORE-2020-012](https://www.drupal.org/sa-core-2020-012)) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: [SA-CORE-2019-010](https://www.drupal.org/sa-core-2019-010)). However, the protections for these two vulnerabilities previously did not work correctly together. As a result, if the site were configured to allow the upload of files with an `htaccess` extension, these files' filenames would not be properly sanitized. This could allow bypassing the protections provided by Drupal core's default `.htaccess` files and possible remote code execution on Apache web servers. This issue is mitigated by the fact that it requires a field administrator to explicitly configure a file field to allow `htaccess` as an extension (a restricted permission), or a contributed module or custom code that overrides allowed file uploads.
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| drupal | — | — |
| drupal/core | 9.4.0 | 9.4.3 |
References
Similar Threats
- Medium CVE-2020-11022
- Medium CVE-2020-11023
- High CVE-2020-28948
- High CVE-2020-36193
- Medium CVE-2020-13662
Free Vulnerability Check
Is your WordPress site affected?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.