Drupal Releases Security Update
Security update addresses a vulnerability affecting iframe domain setting validation
Summary
Security update addresses a vulnerability affecting iframe domain setting validation
Threat details
Prior versions of Drupal
All versions of Drupal 9 prior to 9.3.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Drupal 7 core does not include the Media module and therefore is not affected.
Introduction
Drupal has released a security update to address a moderately critical vulnerability where the Media oEmbed iframe route does not properly validate the iframe domain setting. This vulnerability could lead to cross-site scripting, leaked cookies, or other vulnerabilities.
An attacker could exploit this vulnerability to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review Drupal security advisory SA-CORE-2022-015 and apply the relevant update.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 22 July 2022 4:32 pm