Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 012

fstec логотип

BDU:2022-03953

около 4 лет назад

Уязвимость клиентской HTTP-библиотеки Guzzle интерпретатора языка программирования PHP, связанная с неправильно реализованной проверкой безопасности для стандартных элементов, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-03942

около 4 лет назад

Уязвимость клиентской HTTP-библиотеки Guzzle интерпретатора языка программирования PHP, связанная с ошибками авторизации, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f2wf-25xc-69c9

около 4 лет назад

Failure to strip the Cookie header on change in host or HTTP downgrade

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w248-ffj2-4v5q

около 4 лет назад

Fix failure to strip Authorization header on HTTP downgrade

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-29248

около 4 лет назад

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2022-29248

около 4 лет назад

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2022-29248

около 4 лет назад

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-cwmx-hcrq-mhc3

около 4 лет назад

Cross-domain cookie leakage in Guzzle

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-qf2g-mrrx-rr5p

около 4 лет назад

Drupal Core Cross-site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m648-hpf8-qcjw

около 4 лет назад

Drupal Core Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2022-03953

Уязвимость клиентской HTTP-библиотеки Guzzle интерпретатора языка программирования PHP, связанная с неправильно реализованной проверкой безопасности для стандартных элементов, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
2%
Низкий
около 4 лет назад
fstec логотип
BDU:2022-03942

Уязвимость клиентской HTTP-библиотеки Guzzle интерпретатора языка программирования PHP, связанная с ошибками авторизации, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-f2wf-25xc-69c9

Failure to strip the Cookie header on change in host or HTTP downgrade

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-w248-ffj2-4v5q

Fix failure to strip Authorization header on HTTP downgrade

CVSS3: 7.5
2%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-29248

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware.

CVSS3: 8
1%
Низкий
около 4 лет назад
debian логотип
CVE-2022-29248

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 ...

CVSS3: 8
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-29248

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware.

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-cwmx-hcrq-mhc3

Cross-domain cookie leakage in Guzzle

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-qf2g-mrrx-rr5p

Drupal Core Cross-site scripting vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-m648-hpf8-qcjw

Drupal Core Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 8.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться