Drupal Multiple Vulnerabilities
Last Update Date:
2 Nov 2018 10:48
Release Date:
2 Nov 2018
5292
Views
RISK: Medium Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities have been identified in Drupal. A remote user can exploit these vulnerabilities to disclose sensitive information and bypass security restriction on the targeted system.
Impact
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Decoupled Router module 8.x-1.0, 8.x-1.1
- Session Limit module 7.x-2.2, 8.x-1.0-beta2
- Paragraphs module 8.x-1.4
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Decoupled Router module: If you are running 8.x, upgrade to Decoupled Router 8.x-1.2.
- Session Limit module: If you are running 7.x, upgrade to Session Limit module 7.x-2.3.
- Session Limit module: If you are running 8.x, upgrade to Session Limit module 8.x-1.0-beta3.
- Paragraphs module: If you are running 8.x, upgrade to Paragraphs 8.x-1.5.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with