Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Several Vulnerabilities Patched in Drupal 7, 8

Drupal developers have released updates for versions 7 and 8 to address security flaws that can lead to information disclosure, cache poisoning, redirection to third-party sites and a denial-of-service (DoS) condition.

Drupal developers have released updates for versions 7 and 8 to address security flaws that can lead to information disclosure, cache poisoning, redirection to third-party sites and a denial-of-service (DoS) condition.

Drupal 7.52 and Drupal 8.2.3 patch a total of four vulnerabilities rated “moderately critical” and “less critical.”

One of the more serious issues affecting Drupal 8 can be exploited to cause a DoS condition using specially crafted URLs via the transliteration mechanism, which cleans filenames by replacing certain characters, such as the ones used in Russian and Greek, with universally displayable US-ASCII characters.

A moderately critical flaw in Drupal 7 can allow attackers, in certain circumstances, to construct a confirmation form URL that redirects users to third-party websites after interacting with the form. This vulnerability can be useful for social engineering attacks.

The user password reset form in Drupal 8 fails to specify a proper cache context, allowing cache poisoning attacks and unwanted content on the page.

A “less critical” vulnerability affecting both Drupal 7 and 8 is related to inconsistent names for term access queries. The issue can lead to information on taxonomy terms being disclosed to unprivileged users.

Advertisement. Scroll to continue reading.

These security holes were discovered by external researchers and a member of the Drupal Security Team.

It’s not uncommon for Drupal vulnerabilities to be exploited in the wild. In mid-September, experts warned that a highly critical flaw patched in July had been exploited in attacks aimed at Drupal websites.

Unfortunately, many website administrators leave their Drupal installations unpatched for extended periods of time. For example, the vulnerability dubbed Drupalgeddon, which developers patched in October 2014, had still been exploited to hack websites more than 19 months later.

Related: Drupal Patches Critical Vulnerabilities in Three Modules

Related: Restriction Bypass, XSS Flaws Patched in Drupal 8

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Daniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.

Allied Universal has named Jordan Avnaim Global Chief Information Security Officer.

Cycode has promoted Seth Robbins to President and Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.