Drupal Releases Security Update
Security update addresses a vulnerability in the third-party library Guzzle
Summary
Security update addresses a vulnerability in the third-party library Guzzle
Threat details
Introduction
Drupal has released a security update to address a vulnerability in the third-party library Guzzle that could allow a malicious server to set cookies for unrelated domains. A remote attacker could exploit this vulnerability to take control of an affected website.
Remediation advice
Affected organisations are encouraged to review Drupal security advisory SA-CORE-010 and apply the relevant update.
Definitive source of threat updates
Last edited: 27 May 2022 3:57 pm