Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian 9: DLA-2637-1 Critical Threat From Drupal7 Sanitization Flaw

debian lts
Calendar Grey April 23, 2021
Dist Debian Esm H88
Update Drupal 7 on Debian 9 in response to the cross-origin scripting vulnerability disclosed on April 23, 2021.
The Drupal project identified a vulnerability in the sanitization performed in the _filter_xss_arttributes function, potentially allowing a cross-site scripting, and granted it the...

Summary

https://

No CVE number has been announced.

For Debian 9 "Stretch", the fix to this issue was backported in
version 7.52-2+deb9u15.

We recommend you upgrade your drupal7 package.

For detailed security status of drupal7, please refer to its security
tracker page:



Further information about Debian LTS security advisories, how to
apply these updates to your system, and other frequently asked
questions can be found at:

https://wiki.debian.org/LTS




Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here