Drupal 8 core RESTful Web Services RCE

Published on 16 Jun 2021
Vulnerability

The CVE-2019–6340 remote code execution flaw in Drupal 8’s REST API module affects websites that use the Drupal REST API option. This vulnerability occurs when some other web services module is allowed on the server, such as JSON-API in Drupal 8 or REST services in Drupal 7, or when the Drupal 8 core RESTful API Services module is enabled on the site, enabling users to send GET, PATCH, and POST requests to the server. Despite the fact that the PATCH method is disabled, a GET request is enough to cause the code execution flaw. By sending a malicious GET request to the /node/id API endpoint with a serialized payload, an attacker can take over control of the vulnerable Drupal website (command to execute in server).

Mitigation / Precaution

  • It is advised to upgrade Drupal to the most recent versions with security patches, such as versions 8.6.10 and 8.5.11.
  • If you are using Drupal 7, upgrade all modules.
Rejah Rehim
Written by
Co-founder, Director

Rejah brings more than 12 years of industry experience in Information Technology. He is a fervent security enthusiast and serves as a Project Leader at OWASP Foundation, and Commander (Hon.) at Kerala Police. He has authored two books titled “Effective Python Penetration Testing” and “Python Penetration Testing Cookbook” and is the creator of 9 Mozilla add-ons.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo