Vulnerability Bulletins

Drupal core - Critical - Multiple vulnerabilities - SA-CORE-2022-016


System information

   
Affected software Drupal

Description

Project: Drupal coreDate: 2022-September-28Security risk: Critical 18∕25 AC:Basic/A:Admin/CI:All/II:All/E:Proof/TD:AllVulnerability: Multiple vulnerabilitiesAffected versions: >= 8.0.0 = 9.4.0 CVE IDs: CVE-2022-39261Description: Drupal uses the Twig third-party library for content templating and sanitization. Twig has released a security update that affects Drupal. Twig has rated the vulnerability as high severity. Drupal cores code extending Twig has also been updated to mitigate a

More info:

https://www.drupal.org/sa-core-2022-016

Standar resources

Property Value
CVE CVE-2022-39261.

Version history

Version Comments Date
1.0 Advisory issued 2022-09-29
Ministerio de Defensa
CNI
CCN
CCN-CERT