Monday, May 19, 2025
HomeCVE/vulnerabilityDrupal releases Security update for Multiple Vulnerabilities

Drupal releases Security update for Multiple Vulnerabilities

Published on

SIEM as a Service

Follow Us on Google News

Drupal is a content management software. It’s utilized to make a considerable amount of the websites and applications you utilize each day. Its tools help you to build the versatile, organized content that dynamic web experience require.

Drupal is a platform the United States, London, France, and more use to communicate with the citizen. It’s the system media organizations like BBC, NBC, and MTV UK relies on to educate and engage the world.

Vulnerabilities 

This release also incorporates a security-related update for the PHPUnit dev dependency.

- Advertisement - Google News
  • Editor module incorrectly checks access to inline private files – Drupal 8 – Access Bypass – Critical – CVE-2017-6377

    While including a private file with a configured text editor (like CKEditor), the editor won’t accurately check access for the record being added, which ends up in an access bypass.

  • Some admin paths were not protected with a CSRF token – Drupal 8 – Cross Site Request Forgery – Moderately Critical – CVE-2017-6379

    Some administrative paths did exclude security for CSRF. This would permit an attacker to destroy a few block on a site. This issue is alleviated by the way that clients would need to know the block ID.

  • Remote code execution – Drupal 8 – Remote code execution – Moderately Critical – CVE-2017-6381

    A 3rd party development library incorporating with Drupal 8 development dependencies is helpless against remote code execution.

    This is relieved by the default .htaccess protection against PHP execution, and the way that Composer development dependencies aren’t installed normally.

    With version8.2.7 update guarantees that Drupal core requires the most secure version of PHPUnit accessible, so you should update any sites that do include dev dependencies with this version.

No progressions have been made to the .htaccess, web.config, robots.txt or default settings.php documents in this release, so upgrading custom variants of those records is not required.

Recommend Fix

Upgrade to Drupal 8.2.7 to fix the issue, Your can download Drupal 8.2.7 .

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Pwn2Own Day 3: Zero-Day Exploits Windows 11, VMware ESXi, and Firefox

The Pwn2Own Berlin 2025 last day ended with impressive technological accomplishments, bringing the total...

GNU C(glibc) Vulnerability Let Attackers Execute Arbitrary Code on Millions of Linux Systems

Security researchers have disclosed a significant vulnerability in the GNU C Library (glibc), potentially...

Exploiting dMSA for Advanced Active Directory Persistence

Security researchers have identified new methods for achieving persistence in Active Directory environments by...

VMware ESXi, Firefox, Red Hat Linux & SharePoint Hacked – Pwn2Own Day 2

Security researchers demonstrated their prowess on the second day of Pwn2Own Berlin 2025, discovering...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

PoC Code Published for Linux nftables Security Vulnerability

Security researchers have published proof-of-concept (PoC) exploit code for CVE-2024-26809, a high-severity double-free vulnerability in...

Cisco IOS XE Vulnerability Allows Attackers to Gain Elevated Privileges

Cisco has issued an urgent security advisory (ID: cisco-sa-iosxe-privesc-su7scvdp) following the discovery of multiple...

Cisco IOS, XE, and XR Vulnerability Allows Remote Device Reboots

 Cisco has issued an urgent security advisory (cisco-sa-twamp-kV4FHugn) warning of a critical vulnerability in...