Drupal Releases Security Update
Out-of-band security update addresses two additional vulnerabilities in the third-party library Guzzle
Summary
Out-of-band security update addresses two additional vulnerabilities in the third-party library Guzzle
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Drupal has released an out-of-band security update to address two vulnerabilities in the third-party library Guzzle. This advisory follows the previous Drupal advisory, which related to another Guzzle vulnerability.
These vulnerabilities relate to how the Guzzle library strips the cookie header and the authorisation header. An attacker could exploit these vulnerabilities to take control of an affected website.
Remediation advice
Affected organisations are encouraged to review Drupal security advisory SA-CORE-2022-011 and apply the relevant update.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 14 June 2022 3:49 pm