Project:
Date:
2020-November-18
Vulnerability:
Remote Code Execution
Description:
Media oEmbed does not properly sanitize certain filenames as described in SA-CORE-2020-012.
Solution:
Install the latest version:
- Upgrade to Media oEmbed 7.x-2.8
Reported By:
- Alex Pott of the Drupal Security Team
Fixed By:
- Samuel Mortenson of the Drupal Security Team
- Alex Pott of the Drupal Security Team
- Drew Webber of the Drupal Security Team
Coordinated By:
- Samuel Mortenson of the Drupal Security Team
- Alex Pott of the Drupal Security Team
- Drew Webber of the Drupal Security Team
- xjm of the Drupal Security Team