Tuesday, March 5, 2024

Drupal releases Security update for Multiple Vulnerabilities

Drupal is a content management software. It’s utilized to make a considerable amount of the websites and applications you utilize each day. Its tools help you to build the versatile, organized content that dynamic web experience require.

Drupal is a platform the United States, London, France, and more use to communicate with the citizen. It’s the system media organizations like BBC, NBC, and MTV UK relies on to educate and engage the world.

Vulnerabilities 

This release also incorporates a security-related update for the PHPUnit dev dependency.

  • Editor module incorrectly checks access to inline private files – Drupal 8 – Access Bypass – Critical – CVE-2017-6377

    While including a private file with a configured text editor (like CKEditor), the editor won’t accurately check access for the record being added, which ends up in an access bypass.

  • Some admin paths were not protected with a CSRF token – Drupal 8 – Cross Site Request Forgery – Moderately Critical – CVE-2017-6379

    Some administrative paths did exclude security for CSRF. This would permit an attacker to destroy a few block on a site. This issue is alleviated by the way that clients would need to know the block ID.

  • Remote code execution – Drupal 8 – Remote code execution – Moderately Critical – CVE-2017-6381

    A 3rd party development library incorporating with Drupal 8 development dependencies is helpless against remote code execution.

    This is relieved by the default .htaccess protection against PHP execution, and the way that Composer development dependencies aren’t installed normally.

    With version8.2.7 update guarantees that Drupal core requires the most secure version of PHPUnit accessible, so you should update any sites that do include dev dependencies with this version.

No progressions have been made to the .htaccess, web.config, robots.txt or default settings.php documents in this release, so upgrading custom variants of those records is not required.

Recommend Fix

Upgrade to Drupal 8.2.7 to fix the issue, Your can download Drupal 8.2.7 .

Website

Latest articles

CACTUS Hackers Exploiting Software Bug to Attack Corporate Networks

Threat actors known as CACTUS orchestrated a sophisticated attack on two companies simultaneously, exploiting...

GTPDOOR – Previously Unknown Linux Malware Attack Telecom Networks

Researchers have discovered a new backdoor named GTPDOOR that targets telecommunication network systems within...

US Court Orders NSO Group to Handover Code for Spyware, Pegasus to WhatsApp

Meta, the company that owns WhatsApp, filed a lawsuit against NSO Group in 2019....

New SSO-Based Phishing Attack Trick Users into Sharing Login Credentials  

Threat actors employ phishing scams to trick individuals into giving away important details like...

U.S. Charged Iranian Hacker, Rewards up to $10 Million

The United States Department of Justice (DoJ) has charged an Iranian national, Alireza Shafie...

Huge Surge in Ransomware-as-a-Service Attacks targeting Middle East & Africa

The Middle East and Africa (MEA) region has witnessed a surge in ransomware-as-a-service (RaaS)...

New Silver SAML Attack Let Attackers Forge Any SAML Response To Entra ID

SolarWinds cyberattack was one of the largest attacks of the century in which attackers...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Live Account Takeover Attack Simulation

Live Account Take Over Attack

Live Webinar on How do hackers bypass 2FA ,Detecting ATO attacks, A demo of credential stuffing, brute force and session jacking-based ATO attacks, Identifying attacks with behaviour-based analysis and Building custom protection for applications and APIs.

Related Articles