Skip to main content

Drupal Releases Security Update


Out-of-band security update addresses two additional vulnerabilities in the third-party library Guzzle

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary


Out-of-band security update addresses two additional vulnerabilities in the third-party library Guzzle


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Drupal has released an out-of-band security update to address two vulnerabilities in the third-party library Guzzle. This advisory follows the previous Drupal advisory, which related to another Guzzle vulnerability.

These vulnerabilities relate to how the Guzzle library strips the cookie header and the authorisation header. An attacker could exploit these vulnerabilities to take control of an affected website.


Remediation advice

Affected organisations are encouraged to review Drupal security advisory SA-CORE-2022-011 and apply the relevant update.



CVE Vulnerabilities

Last edited: 14 June 2022 3:49 pm