CVE-2019-6342

Drupal core - Critical - Access bypass - SA-CORE-2019-008

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.


We have discovered 137,513 live websites that are affected by CVE-2019-6342.

Test my site




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains137,513 live websites (54.74% of Drupal install base)
Vulnerable Versions
  • from 0 before 8.7.4
Vulnerable Versions Count96 versions ( 31.48% of all versions)



Details

  • Published - May 29, 2020
  • Updated - Aug 4, 2024

CVE-2019-6342 usage by Country

United States42,849 websites



Germany14,199 websites
Russia12,118 websites
France10,614 websites
GB4,308 websites
Belgium4,063 websites
Netherlands3,745 websites
Italy3,470 websites
Spain2,936 websites
Canada2,677 websites

CVE-2019-6342 usage by TLD

.com37,873 websites
.org11,761 websites
.ru10,043 websites
.de7,359 websites
.fr5,019 websites
.be4,479 websites
.edu4,044 websites
.net3,350 websites
.it3,003 websites
.nl2,806 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-6342

Top websites that are affected by CVE-2019-6342. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States***
***.org United States*,***
********.gov United States*,***
******.gov United States*,***
***.**.gov United States*,***
******.edu United States*,***
***.gov United States*,***
****.org United States*,***
***.com United States*,***
*******.com Netherlands*,***
See full domain list

FAQ

A total of 137,513 websites have been identified as vulnerable to CVE-2019-6342, discovered through global website indexing conducted by WebTechSurvey.
Drupal is susceptible to CVE-2019-6342 vulnerability.
Drupal versions before 8.7.4 are vulnerable to CVE-2019-6342.
Version 8.7.4 of Drupal addresses the CVE-2019-6342 security vulnerability.