Description
Drupal Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to bypass certain security restrictions and perform otherwise restricted actions. Drupal Core versions 8.x ranging from 8.0.0 and up to and including 8.5.5 are vulnerable.
Remediation
Update to Drupal Core version 8.5.6 or latest
References
https://www.drupal.org/SA-CORE-2018-005
https://symfony.com/blog/cve-2018-14773-remove-support-for-legacy-and-risky-http-headers
https://framework.zend.com/security/advisory/ZF2018-01
https://drupal.stackexchange.com/questions/266784/how-critical-is-sa-core-2018-005
Related Vulnerabilities
WordPress Plugin Login Widget With Shortcode Cross-Site Request Forgery (3.1.1)
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.4.17)
WordPress Plugin Log Emails Information Disclosure (1.0.6)
PHP Numeric Errors Vulnerability (CVE-2016-10158)
WordPress Plugin Tutor LMS-eLearning and online course solution Security Bypass (2.7.0)