Skip to main content

Drupal Releases Security Update

Security update addresses a vulnerability affecting iframe domain setting validation

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security update addresses a vulnerability affecting iframe domain setting validation


Affected platforms

The following platforms are known to be affected:

Threat details

Prior versions of Drupal

All versions of Drupal 9 prior to 9.3.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.

Drupal 7 core does not include the Media module and therefore is not affected.


Introduction

Drupal has released a security update to address a moderately critical vulnerability where the Media oEmbed iframe route does not properly validate the iframe domain setting. This vulnerability could lead to cross-site scripting, leaked cookies, or other vulnerabilities.

An attacker could exploit this vulnerability to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review Drupal security advisory SA-CORE-2022-015 and apply the relevant update.


Definitive source of threat updates


Last edited: 22 July 2022 4:32 pm