CVE-2019-6341: Debian Linux

Medium severity, CVSS 5.4. EPSS: 12.2% chance of exploitation in the next 30 days.

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Drupal Drupal: from 7.0, before 7.65 (fixed in 7.65); from 8.5.0, before 8.5.14 (fixed in 8.5.14); from 8.6.0, before 8.6.13 (fixed in 8.6.13)
  • Fedoraproject Fedora: version 28 only; version 29 only

Published 2019-03-26. Last modified 2026-06-17.