QID 154121
Date Published: 2022-07-21
QID 154121: Drupal Core: Guzzle Library Improper Input Validation Vulnerability (CVE-2022-24775)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal uses the third-party Guzzle library for handling HTTP requests and responses to external services. Guzzle is vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values.
Affected Versions:
Drupal 8.0.0 to 9.2.15
Drupal 9.3.0 to 9.3.8
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
An attacker could sneak in a new line character and pass untrusted values.
Solution
Customers are advised to install latest Drupal version.
For more information visit Drupal security advisory SA-CORE-2022-006.
For more information visit Drupal security advisory SA-CORE-2022-006.
Vendor References
- SA-CORE-2022-006 -
www.drupal.org/sa-core-2022-006
CVEs related to QID 154121
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-006 |
|