Vulnerability Bulletins

Drupal core - Critical - Multiple vulnerabilities - SA-CORE-2022-016

System information

Affected software Drupal


Project: Drupal coreDate: 2022-September-28Security risk: Critical 18∕25 AC:Basic/A:Admin/CI:All/II:All/E:Proof/TD:AllVulnerability: Multiple vulnerabilitiesAffected versions: >= 8.0.0 = 9.4.0 CVE IDs: CVE-2022-39261Description: Drupal uses the Twig third-party library for content templating and sanitization. Twig has released a security update that affects Drupal. Twig has rated the vulnerability as high severity. Drupal cores code extending Twig has also been updated to mitigate a

More info:

Standar resources

Property Value
CVE CVE-2022-39261.

Version history

Version Comments Date
1.0 Advisory issued 2022-09-29
Ministerio de Defensa
Presidencia española. Consejo de la Unión Europea