Drupal Security Update – 24 September 2023

Drupal has released a security update to fix a vulnerability that affects multiple versions of Drupal Core.

The addressed vulnerability could allow the remote attacker to obtain sensitive information from the affected products by sending specially crafted requests. This vulnerability only affects sites with the JSON: API module enabled and can be mitigated by uninstalling the mentioned module.

Drupal Core Cache Poisoning Vulnerability (SA-CORE-2023-006):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

Affected products:

  • Drupal from 8.7.0 to less than 9.5.11.
  • Drupal from 10.0 to less than 10.0.11.
  • Drupal from 10.1 to less than 10.1.4.
Vulnerabilities

SA-CORE-2023-006

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Drupal Security Advisory

References