Tuesday, July 23, 2024
EHA

Drupal releases Security update for Multiple Vulnerabilities

Drupal is a content management software. It’s utilized to make a considerable amount of the websites and applications you utilize each day. Its tools help you to build the versatile, organized content that dynamic web experience require.

Drupal is a platform the United States, London, France, and more use to communicate with the citizen. It’s the system media organizations like BBC, NBC, and MTV UK relies on to educate and engage the world.

Vulnerabilities 

This release also incorporates a security-related update for the PHPUnit dev dependency.

  • Editor module incorrectly checks access to inline private files – Drupal 8 – Access Bypass – Critical – CVE-2017-6377

    While including a private file with a configured text editor (like CKEditor), the editor won’t accurately check access for the record being added, which ends up in an access bypass.

  • Some admin paths were not protected with a CSRF token – Drupal 8 – Cross Site Request Forgery – Moderately Critical – CVE-2017-6379

    Some administrative paths did exclude security for CSRF. This would permit an attacker to destroy a few block on a site. This issue is alleviated by the way that clients would need to know the block ID.

  • Remote code execution – Drupal 8 – Remote code execution – Moderately Critical – CVE-2017-6381

    A 3rd party development library incorporating with Drupal 8 development dependencies is helpless against remote code execution.

    This is relieved by the default .htaccess protection against PHP execution, and the way that Composer development dependencies aren’t installed normally.

    With version8.2.7 update guarantees that Drupal core requires the most secure version of PHPUnit accessible, so you should update any sites that do include dev dependencies with this version.

No progressions have been made to the .htaccess, web.config, robots.txt or default settings.php documents in this release, so upgrading custom variants of those records is not required.

Recommend Fix

Upgrade to Drupal 8.2.7 to fix the issue, Your can download Drupal 8.2.7 .

Website

Latest articles

Beware Of Dating Apps Exposing Your Personal And Location Details To Cyber Criminals

Threat actors often attack dating apps to steal personal data, including sensitive data and...

Hackers Abusing Google Cloud For Phishing

Threat actors often attack cloud services for several illicit purposes. Google Cloud is targeted...

Two Russian Nationals Charged for Cyber Attacks against U.S. Critical Infrastructure

The United States has designated Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, two members...

Threat Actors Taking Advantage of CrowdStrike BSOD Bug to Deliver Malware

Threat actors have been found exploiting a recently discovered bug in CrowdStrike's software that...

NCA Shut’s Down the Most Popular “digitalstress” DDoS-for-hire Service

The National Crime Agency (NCA) has successfully infiltrated and dismantled one of the most...

Play Ransomware’s Linux Variant Attacking VMware ESXi Servers

A new Linux variant of Play ransomware targets VMware ESXi environments, which encrypts virtual...

SonicOS IPSec VPN Vulnerability Let Attackers Cause Dos Condition

SonicWall has disclosed a critical heap-based buffer overflow vulnerability in its SonicOS IPSec VPN....
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles