Vulnerability Bulletins

Drupal core - Critical - Drupal core - Critical - Third-party libraries - SA-CORE-2021-004


System information

   
Affected software Drupal

Description

Project: Drupal coreDate: 2021-July-21Security risk: Critical 15∕25 AC:Complex/A:User/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Drupal core - Critical - Third-party librariesCVE IDs: CVE-2021-32610Description: The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal.The vulnerability is mitigated by the fact that Drupal cores use of the Archive_Tar library is not vulnerable, as it does not permit symlinks.Exploitation may

More info:

https://www.drupal.org/sa-core-2021-004

Standar resources

Property Value
CVE CVE-2021-32610.

Version history

Version Comments Date
1.0 Advisory issued 2021-10-02
Ministerio de Defensa
CNI
CCN
CCN-CERT