CVE Request for Webform Multiple File

Created on 23 May 2025, 8 days ago

CVE Request

I'm attaching my assessment of Vulnogram json file for:

[D7ES] XSS vulnerability on the file name renderer
https://security.drupal.org/node/162249

I used CVSS 4.0 because Vulnogram labels 3.1 as obsolete (though I'm not sure Drupal is ready for CVSS, per another issue I read).

In the assessment I presumed that a web form could be opened up to an unauthenticated user who could upload a malicious file, thus leading to a rating of High/7.

Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/S:N/R:U/V:D/RE:L/U:Amber

Happy to make revisions.

💬 Support request
Status

Active

Version

1.0

Component

Code

Created by

🇺🇸United States aangel

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

  • Issue created by @aangel
  • 🇺🇸United States aangel
  • 🇺🇸United States greggles Denver, Colorado, USA

    Thanks aangel. Moving status. And let's give this a few days for review.

  • 🇮🇹Italy bigbabert Milano, Italy

    Hi why there is link to security private issue? should not remain private? https://security.drupal.org/node/162249

  • 🇺🇸United States cmlara

    Question:
    It appears from the description the vulnerability was in a 3rd party product that was copied into the the module.

    Would the module hosted on D.O. actually be the supplier of the vulnerable product in this case?

    Would section 4.3 of the CNA v4.1.0 rules come into play here?

    4.3.2 If a CNA is considering an assignment, and the CNA is not the Supplier of the vulnerable Product, then the CNA SHOULD make a reasonable and good faith effort to notify the Supplier. For example, if an operating system Supplier discovers a Vulnerability in a library from an upstream Supplier, in addition to assigning the CVE ID to the upstream Vulnerability, the operating system Supplier SHOULD attempt to notify the upstream library Supplier. This reduces duplicate CVE ID assignments and helps alert others that may be affected by the Vulnerability.

    This is an interesting grey area, I'm not 100% sure on this one way or the other, bringing this up for discussion since Drupal actively publishing CVE's is a relatively new development and the procedures appear to be still being developed.

Production build 0.71.5 2024