QID 730507

Date Published: 2022-05-30

QID 730507: Drupal Core Moderately Critical Guzzle Vulnerability (SA-CORE-2022-010)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

Affected Versions:
Drupal 9.3.x prior to Drupal 9.3.14
Drupal 9.2.x prior to Drupal 9.2.20
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.

Successful exploitation of these vulnerabilities could affect Confidentiality.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to install latest drupal version.
    For more information visitDrupal security advisory sa-core-2022-010
    Vendor References

    CVEs related to QID 730507

    Software Advisories
    Advisory ID Software Component Link
    sa-core-2022-010 URL Logo www.drupal.org/sa-core-2022-010