Drupal Releases Security Updates
Affected platforms
The following platforms are known to be affected:
Threat details
Prior versions of Drupal
Drupal 9 prior to 9.2.x and Drupal 8 are end-of-life and do not receive security coverage.
Drupal 7, 8, and 9 site owners should review their site following the protocol for managing external libraries and plugins previously suggested by the Drupal Security Team, as contributed projects may use additional CKEditor plugins not packaged in Drupal core.
Introduction
Drupal has released security updates to address cross-site scripting (XSS) and denial-of-service vulnerabilities in the third-party CKEditor library for what-you-see-is-what-you-get (WYSIWYG) editing. An attacker could exploit these vulnerabilities to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review Drupal Security Advisories SA-CORE-2022-005 and apply the necessary updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 18 March 2022 3:53 pm