Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian 8: DLA-2263-1 Critical: Drupal7 Cross-Site Request Issue

debian lts
Calendar Grey June 30, 2020
Dist Debian Esm H88
A patch for Drupal7 tackles CVE-2020-13663, a vital flaw in cross-site request handling. Users are urged to update promptly to ensure security.
CVE-2020-13663 - Drupal SA 2020-004 The Drupal core Form API does not properly handle certain form

Summary

The Drupal core Form API does not properly handle certain form
input from cross-site requests, which can lead to other vulnerabilities.

For Debian 8 "Jessie", this problem has been fixed in version
7.32-1+deb8u19.

We recommend that you upgrade your drupal7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: drupal7
Version: 7.32-1+deb8u19
CVE ID: CVE-2020-13663
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here