Skip to main content

Drupal Releases Out-Of-Band Security Updates

Drupal has released out-of-band security updates to address a vulnerability in Drupal 9

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Drupal has released out-of-band security updates to address a vulnerability in Drupal 9


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Drupal has released out-of-band security updates to address a vulnerability in the third-party Guzzle library for handling HTTP requests and responses to external services. The vulnerability, tracked as CVE-2022-24775, relates to improper header parsing in the HTTP message library, guzzlehttp/psr7, which can allow untrusted values to be passed. An attacker could exploit this vulnerability to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review Drupal Security Advisories SA-CORE-2022-006 and apply the necessary updates.


Definitive source of threat updates


Last edited: 23 March 2022 12:23 pm