CVE-2019-6338

Source
https://cve.org/CVERecord?id=CVE-2019-6338
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-6338.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-6338
Aliases
Downstream
Published
2019-01-22T14:29:00Z
Modified
2026-07-08T05:55:37Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                },
                {
                    "introduced": "9.0"
                },
                {
                    "last_affected": "9.0"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "debian:debian_linux"
        }
    ]
}
References

Affected packages

Git / github.com/drupal/drupal

Affected ranges

Type
GIT
Repo
https://github.com/drupal/drupal
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.0"
        },
        {
            "fixed": "7.62"
        },
        {
            "introduced": "8.5.0"
        },
        {
            "fixed": "8.5.9"
        },
        {
            "introduced": "8.6.0"
        },
        {
            "fixed": "8.6.6"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

7.*
7.0
7.10
7.12
7.14
7.15
7.17
7.22
7.23
7.25
7.28
7.30
7.33
7.36
7.37
7.4
7.40
7.42
7.43
7.50
7.51
7.54
7.55
7.56
7.6
7.61
7.7
7.8
7.9
8.*
8.5.0
8.5.4
8.5.5
8.5.7
8.5.8
8.6.0
8.6.1
8.6.3
8.6.4
8.6.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-6338.json"