Skip to main content

Drupal Multiple Vulnerabilities

Last Update Date: 2 Nov 2018 10:48 Release Date: 2 Nov 2018 4398 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities have been identified in Drupal. A remote user can exploit these vulnerabilities to disclose sensitive information and bypass security restriction on the targeted system.


Impact

  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Decoupled Router module 8.x-1.0, 8.x-1.1
  • Session Limit module 7.x-2.2, 8.x-1.0-beta2
  • Paragraphs module 8.x-1.4

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Decoupled Router module: If you are running 8.x, upgrade to Decoupled Router 8.x-1.2.
  • Session Limit module: If you are running 7.x, upgrade to Session Limit module 7.x-2.3.
  • Session Limit module: If you are running 8.x, upgrade to Session Limit module 8.x-1.0-beta3.
  • Paragraphs module: If you are running 8.x, upgrade to Paragraphs 8.x-1.5.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link