Drupal Releases Out-Of-Band Security Updates
Drupal has released out-of-band security updates to address a vulnerability in Drupal 9
Summary
Drupal has released out-of-band security updates to address a vulnerability in Drupal 9
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Drupal has released out-of-band security updates to address a vulnerability in the third-party Guzzle library for handling HTTP requests and responses to external services. The vulnerability, tracked as CVE-2022-24775, relates to improper header parsing in the HTTP message library, guzzlehttp/psr7, which can allow untrusted values to be passed. An attacker could exploit this vulnerability to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review Drupal Security Advisories SA-CORE-2022-006 and apply the necessary updates.
Definitive source of threat updates
Last edited: 23 March 2022 12:23 pm