QID 154088
Date Published: 2022-01-13
QID 154088: Drupal Core Multiple Vulnerabilities (SA-CORE-2020-008 - SA-CORE-2020-011)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License. The Current Installation of Drupal suffers from Multiple vulnerabilities such as Cross-Site Scripting, Access Control Bypass and Information Disclosure.
Affected Versions:
Drupal 8.8.x, prior to Drupal 8.8.10.
Drupal 8.9.x, prior to Drupal 8.9.6.
Drupal 9.0.x, prior to Drupal 9.0.6.
QID Detection Logic:
This QID checks for vulnerable version of Drupal installed on the target via a version based check.
Successful exploitation of the Cross-Site Scripting, Access Control Bypass and Information Disclosure vulnerabilities will affect the Confidentiality of the application.
Solution
Customers are advised upgrading to the latest Drupal version or to the versions specified in the below official advisory.
For more information visit Drupal security advisory SA-CORE-2020-011 Drupal security advisory SA-CORE-2020-010 Drupal security advisory SA-CORE-2020-009 Drupal security advisory SA-CORE-2020-008
For more information visit Drupal security advisory SA-CORE-2020-011 Drupal security advisory SA-CORE-2020-010 Drupal security advisory SA-CORE-2020-009 Drupal security advisory SA-CORE-2020-008
Vendor References
- SA-CORE-2020-008 -
www.drupal.org/sa-core-2020-008 - SA-CORE-2020-009 -
www.drupal.org/SA-CORE-2020-009 - SA-CORE-2020-010 -
www.drupal.org/sa-core-2020-010 - SA-CORE-2020-011 -
www.drupal.org/sa-core-2020-011
CVEs related to QID 154088
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| sa-core-2020-008 |
|
||
| sa-core-2020-009 |
|
||
| sa-core-2020-010 |
|
||
| sa-core-2020-011 |
|