Executive brief
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. Attackers can exploit multiple attack vectors to compromise the site, a flaw related to the previous SA-CORE-2018-002 (Drupalgeddon 2) vulnerability.
Affected products
- Drupal Drupal Core 7.x, 8.x (specifically < 7.59, 8.4.x < 8.4.8, 8.5.x < 8.5.3)
Timeline
- 2018-04-25: disclosed: SA-CORE-2018-004 / CVE-2018-7602 published by Drupal.org
- 2018-04-25: patched: Security updates released for Drupal 7.59, 8.4.8, and 8.5.3
- 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2018-04-25: exploited: Reported as being exploited in the wild at the time of disclosure.