Drupal core
This is the underlying software that runs the entire website and manages all the content.
A flaw allows anyone on the internet to view any private information stored in the website database. They could also alter any content or add their own computer code to take over the system.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected by the main flaw if it uses a PostgreSQL database, and it might be affected by other underlying software flaws depending on its setup and extra features.
- Has it been used in attacksYes. It has been used in real attacks.
- How urgentDrupal rates this highly critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Drupal core to 10.6.9, 11.3.10, 10.5.10, 10.4.10 or 11.2.12, whichever branch you are on.
For developers: what the fix changed
The fix prevents SQL injection by ensuring that array values in SQL conditions are re-indexed using `array_values()` in `Condition::compile`, `ConditionAggregate::compile`, and the PostgreSQL-specific `Condition::translateCondition`, which stops malicious associative array keys from being injected into the query.
Also in this release The release also updated Symfony, Twig, and Underscore.js dependencies, and bumped the Drupal core version to 10.6.9.
composer.json+1 −1composer.lock+0 −0composer/Metapackage/CoreRecommended/composer.json+32 −32composer/Metapackage/DevDependencies/composer.json+1 −1composer/Metapackage/PinnedDevDependencies/composer.json+9 −9core/assets/vendor/underscore/underscore-min.js+0 −0core/assets/vendor/underscore/underscore-min.js.map+0 −0core/composer.json+6 −6core/core.libraries.yml+2 −2core/lib/Drupal.php+1 −1core/lib/Drupal/Component/DependencyInjection/composer.json+1 −1core/lib/Drupal/Component/EventDispatcher/composer.json+1 −1