Drupal Alert
8179Warning Date
Severity Level
Warning Number
Target Sector
24 August, 2023
● Critical
2023-5749
All
Description:
Drupal has released security updates to address multiple vulnerabilities in the following products:
- ACL module for Drupal 7.x
- ACL module 8.x-1.0-beta3 or below
- Forum Access module for Drupal 7.x
- Forum Access module 8.x-1.0-beta3 or below
- Flexi Access module for Drupal 7.x
- Config Pages module for Drupal 8+
- Shorthand module for Drupal 8+
- SafeDelete module for Drupal 8/9 or 10
- Data Field module for Drupal 1.x
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Arbitrary Code Execution
- Information Disclosure
- Access Bypass
Best practice and Recommendations:
The CERT team encourages users to update the affected versions and to review Drupal security advisory: