{ "canonical_id": "drupal--284d6aff2f", "system_id": "drupal", "display_name": "Drupal", "category": "cms", "advisory_mode": "core", "title": "Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002", "summary": "
Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.
\nThe issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
Install the latest version:
\nAll versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
\nThis advisory is not covered by Drupal Steward.