Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 9: DLA-2889-1 Critical: Drupal 7 jQuery Security Fix

debian lts
Calendar Grey January 19, 2022
Dist Debian Esm H88
Security advisory for Drupal 7.52 focuses on jQuery weakness mitigation to thwart cross-site scripting threats. Prompt upgrade advised.
The Drupal project includes a very old version of jQuery

Summary

Drupal is a rich Web content management system; it was included in
Debian until Stretch, but is not present in any newer releases. If you
run a web server with Drupal7, we strongly recommend you to upgrade
the drupal7 package.

For the detailed security status of drupal7 please refer to its
security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: drupal7
Version: 7.52-2+deb9u17
CVE ID: CVE-2021-41182 CVE-2021-41183 CVE-2016-7103 CVE-2010-5312

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here