Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 029
GHSA-w7qx-vwr9-2j3r
Drupal editor module incorrectly checks access to inline private files
GHSA-h377-287m-w2r9
Drupal file REST resource does not properly validate
GHSA-p8g6-5mg7-9r5q
Drupal REST API can bypass comment approval
GHSA-58f3-cx8p-h8jg
Drupal core access bypass vulnerability
GHSA-5vwg-c233-4qjm
Cross-site request forgery (CSRF) vulnerability in the BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that login a user to another web site.
GHSA-j7rr-r9x8-9jvj
Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-2.0-alpha3 for Drupal allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.
GHSA-vp7c-82j8-vfqp
The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."
GHSA-367f-3f3f-6cpx
The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.
GHSA-3gx6-h57h-rm27
Drupal Core Remote Code Execution Vulnerability
GHSA-9m8p-564h-5p6w
Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-w7qx-vwr9-2j3r Drupal editor module incorrectly checks access to inline private files | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-h377-287m-w2r9 Drupal file REST resource does not properly validate | CVSS3: 5.9 | 2% Низкий | около 4 лет назад | |
GHSA-p8g6-5mg7-9r5q Drupal REST API can bypass comment approval | CVSS3: 7.4 | 2% Низкий | около 4 лет назад | |
GHSA-58f3-cx8p-h8jg Drupal core access bypass vulnerability | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-5vwg-c233-4qjm Cross-site request forgery (CSRF) vulnerability in the BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that login a user to another web site. | 1% Низкий | около 4 лет назад | ||
GHSA-j7rr-r9x8-9jvj Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-2.0-alpha3 for Drupal allow remote attackers to hijack the authentication of arbitrary users via unknown vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-vp7c-82j8-vfqp The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache." | 1% Низкий | около 4 лет назад | ||
GHSA-367f-3f3f-6cpx The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved. | 1% Низкий | около 4 лет назад | ||
GHSA-3gx6-h57h-rm27 Drupal Core Remote Code Execution Vulnerability | CVSS3: 8.1 | 92% Критический | около 4 лет назад | |
GHSA-9m8p-564h-5p6w Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message. | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу