QID 154119
Date Published: 2022-07-14
QID 154119: Drupal Core: Guzzle Library Multiple Vulnerabilities (CVE-2022-31043,CVE-2022-31042)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal uses the third-party Guzzle library for handling HTTP requests and responses to external services. Guzzle has multiple vulnerabilities:
CVE-2022-31042 : Failure to strip the Cookie header on change in host or HTTP downgrade
CVE-2022-31043 : Fix failure to strip Authorization header on HTTP downgrade
Affected Versions:
Drupal 9.2.0 to 9.2.20
Drupal 9.3.0 to 9.3.15
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
For more information visit Drupal security advisory SA-CORE-2022-011.
- SA-CORE-2022-011 -
www.drupal.org/sa-core-2022-011
CVEs related to QID 154119
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-011 |
|