Vulnerability Bulletins

Drupal Core - Highly Critical - Injection - SA-CORE-2016-003

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2016-003Project: Drupal core Version: 8.xDate: 2016-July-18Security risk: 20/25 ( Highly Critical) AC:Basic/A:None/CI:All/II:All/E:Proof/TD:DefaultVulnerability: InjectionDescriptionDrupal 8 uses the third-party PHP library Guzzle for making server-side HTTP requests. An attacker can provide a proxy server that Guzzle will use. The details of this are explained at https://httpoxy.org/.CVE identifier(s) issuedCVE-2016-5385Versions affectedDrupal core 8.x versions

More info:

https://www.drupal.org/SA-CORE-2016-003