Drupal patches access bypass vulnerability

News by Robert Abel

Drupal released a security update to patch an access bypass vulnerability in Drupal Core, which could allow an attacker to take control of an affected website.

Drupal released a security update to patch an access bypass vulnerability in Drupal Core, which could allow an attacker to take control of an affected website.

The problem exists in Drupal 8.7.4, when the experimental Workspaces module is enabled, an access bypass condition is created and can be mitigated by disabling the Workspaces module, according to a 17 July security advisory

If the site is running Drupal 8.7.4, users should upgrade to 8.7.5 while Drupal 8.7.3 and earlier, Drupal 8.6.x and earlier and Drupal 7.x are not affected.

This article was originally published on SC Media US.

Find this article useful?

Get more great articles like this in your inbox every lunchtime

Video and interviews