Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 029
GHSA-qp8q-gwf5-hqh2
Drupal Cross-Site Scripting vulnerability
GHSA-ph8m-2h2f-qgr2
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
GHSA-jq73-c7h9-wr72
Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
GHSA-3gw2-26w5-pcm6
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
GHSA-vqp6-f6x9-5r96
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
GHSA-3v66-h3rq-pj5p
drupal6 version 6.16 has open redirection
BDU:2022-02724
Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю повысить свои привилегии
GHSA-q7rv-6hp3-vh96
Improper Input Validation in guzzlehttp/psr7
CVE-2022-24775
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
CVE-2022-24775
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8 ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-qp8q-gwf5-hqh2 Drupal Cross-Site Scripting vulnerability | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-ph8m-2h2f-qgr2 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-jq73-c7h9-wr72 Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. | 1% Низкий | больше 4 лет назад | ||
GHSA-3gw2-26w5-pcm6 Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. | 1% Низкий | больше 4 лет назад | ||
GHSA-vqp6-f6x9-5r96 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked. | 1% Низкий | больше 4 лет назад | ||
GHSA-3v66-h3rq-pj5p drupal6 version 6.16 has open redirection | 1% Низкий | больше 4 лет назад | ||
BDU:2022-02724 Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю повысить свои привилегии | CVSS3: 5.4 | больше 4 лет назад | ||
GHSA-q7rv-6hp3-vh96 Improper Input Validation in guzzlehttp/psr7 | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
CVE-2022-24775 guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
CVE-2022-24775 guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8 ... | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу