Monday, October 7, 2024
HomeCVE/vulnerabilityDrupal releases Security update for Multiple Vulnerabilities

Drupal releases Security update for Multiple Vulnerabilities

Published on

Drupal is a content management software. It’s utilized to make a considerable amount of the websites and applications you utilize each day. Its tools help you to build the versatile, organized content that dynamic web experience require.

Drupal is a platform the United States, London, France, and more use to communicate with the citizen. It’s the system media organizations like BBC, NBC, and MTV UK relies on to educate and engage the world.

Vulnerabilities 

This release also incorporates a security-related update for the PHPUnit dev dependency.

- Advertisement - EHA
  • Editor module incorrectly checks access to inline private files – Drupal 8 – Access Bypass – Critical – CVE-2017-6377

    While including a private file with a configured text editor (like CKEditor), the editor won’t accurately check access for the record being added, which ends up in an access bypass.

  • Some admin paths were not protected with a CSRF token – Drupal 8 – Cross Site Request Forgery – Moderately Critical – CVE-2017-6379

    Some administrative paths did exclude security for CSRF. This would permit an attacker to destroy a few block on a site. This issue is alleviated by the way that clients would need to know the block ID.

  • Remote code execution – Drupal 8 – Remote code execution – Moderately Critical – CVE-2017-6381

    A 3rd party development library incorporating with Drupal 8 development dependencies is helpless against remote code execution.

    This is relieved by the default .htaccess protection against PHP execution, and the way that Composer development dependencies aren’t installed normally.

    With version8.2.7 update guarantees that Drupal core requires the most secure version of PHPUnit accessible, so you should update any sites that do include dev dependencies with this version.

No progressions have been made to the .htaccess, web.config, robots.txt or default settings.php documents in this release, so upgrading custom variants of those records is not required.

Recommend Fix

Upgrade to Drupal 8.2.7 to fix the issue, Your can download Drupal 8.2.7 .

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Chinese Group Hacked US Court Wiretap Systems

Chinese hackers have infiltrated the networks of major U.S. broadband providers, gaining access to...

19.6K+ Public Zimbra Installations Vulnerable to Code Execution Attacks – CVE-2024-45519

A critical vulnerability in Zimbra's postjournal service, identified as CVE-2024-45519, has left over 19,600...

Prince Ransomware Hits UK and US via Royal Mail Phishing Scam

A new ransomware campaign targeting individuals and organizations in the UK and the US...

Microsoft, DOJ Dismantle Domains Used by Russian FSB-Linked Hacking Group

Microsoft and the U.S. Department of Justice (DOJ) have successfully dismantled a network of...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

Hackers Now Exploit Ivanti Endpoint Manager Vulnerability to Launch Cyber Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new...

CISA Warns of Four Vulnerabilities that Exploited Actively in the Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has warned about four critical vulnerabilities currently...

RansomHub Ransomware Using Multiple Techniques To Disable EDR And Antivirus

The RansomHub ransomware group tracked as Water Bakunawa, employs targeted spear-phishing to exploit the...