Skip to main content

Drupal Releases Security Updates

Report a cyber attack: call 0300 303 5222 or email [email protected]

Threat details

Introduction

Drupal has released security updates to address vulnerabilities in Drupal 7.x, 8.8.x, 8.9.x, and 9.0.x. An attacker could exploit some of these vulnerabilities to obtain sensitive information or leverage the way HTML is rendered.


Remediation advice

Affected organisations are encouraged to review the below Drupal security advisories and apply the relevant updates.


Remediation steps

Type Step
Patch

Drupal core - Moderately critical - Cross-site scripting | SA-CORE-2020-007


https://www.drupal.org/sa-core-2020-007
Patch

Drupal core - Moderately critical - Access bypass | SA-CORE-2020-008


https://www.drupal.org/sa-core-2020-008
Patch

Drupal core - Critical - Cross-site scripting | SA-CORE-2020-009


https://www.drupal.org/sa-core-2020-009
Patch

Drupal core - Moderately critical - Cross-site scripting | SA-CORE-2020-010


https://www.drupal.org/sa-core-2020-010
Patch

Drupal core - Moderately critical - Information disclosure | SA-CORE-2020-011


https://www.drupal.org/sa-core-2020-011

Last edited: 21 September 2020 12:30 pm