-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/core | composer | >= 7.0, < 7.56 | 7.56 |
| drupal/core | composer | >= 8.0, < 8.3.4 | 8.3.4 |
| drupal/drupal | composer | >= 8.0, < 8.3.4 | 8.3.4 |
| drupal/drupal | composer | >= 7.0, < 7.56 | 7.56 |
The vulnerability stems from missing session-based ownership checks for temporary private files. In Drupal's architecture:
A Semantic Attack on Google Gemini - Read the Latest Research