Drupal core - Moderately critical - Denial of Service - SA-CORE-2019-009
https://www.drupal.org/sa-core-2019-009Project: Drupal core (
https://www.drupal.org/project/drupal)Version: 8.8.x-dev8.7.x-devDate: 2019-December-18Security risk: Moderately critical 12∕25 AC:None/A:None/CI:None/II:None/E:Theoretical/TD:AllVulnerability: Denial of ServiceDescription: A visit to install.php can cause cached data to become corrupted. This could cause a site to be impaired until caches are rebuilt.Solution: Install the latest version:
If you are using Drupal 8.7.x, upgrade to Drupal 8.7.11 (
https://www.drupal.org/project/drupal/releases/8.7.11).
If you are using Drupal 8.8.x, upgrade to Drupal 8.8.1 (
https://www.drupal.org/project/drupal/releases/8.8.1).
Versions of Drupal 8 prior to 8.7.x are end-of-life and do not receive security coverage.
To mitigate this issue in any version of Drupal 8, you can also block access to install.php if it's not required.Reported By: Drew Webber (
https://www.drupal.org/user/255969) of the Drupal Security Team
Fixed By: Drew Webber (
https://www.drupal.org/user/255969) of the Drupal Security Team
Lee Rowlands (
https://www.drupal.org/user/395439) of the Drupal Security Team
Heine (
https://www.drupal.org/user/17943) of the Drupal Security Team
Alex Pott (
https://www.drupal.org/user/157725) of the Drupal Security Team
Jess (
https://www.drupal.org/user/65776) of the Drupal Security Team
Damien McKenna (
https://www.drupal.org/user/108450) of the Drupal Security Team
David Snopek (
https://www.drupal.org/user/266527) of the Drupal Security Team
Nathaniel Catchpole (
https://www.drupal.org/user/35733) of the Drupal Security Team
Greg Knaddison (
https://www.drupal.org/user/36762) of the Drupal Security Team