-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/core | composer | >= 8.0.0, < 8.7.12 | 8.7.12 |
| drupal/core | composer | >= 8.8.0, < 8.8.4 | 8.8.4 |
The vulnerability originates from the third-party CKEditor library (specifically versions prior to 4.14), not directly from Drupal's own code. Drupal core becomes vulnerable by including these outdated CKEditor versions. The XSS vulnerability exists in CKEditor's content processing logic (e.g., paste-from-Word/LibreOffice features), but the advisory doesn't specify any particular Drupal PHP functions as vulnerable. The fix involves updating the bundled CKEditor dependency, not modifying Drupal's core functions. Without access to commit diffs or specific Drupal code changes, we can't identify vulnerable Drupal functions with high confidence.
Ongoing coverage of React2Shell