Drupal Releases Security Update
Security update addresses multiple vulnerabilities affecting the Twig library
Summary
Security update addresses multiple vulnerabilities affecting the Twig library
Threat details
Prior versions of Drupal
All versions of Drupal 9 prior to 9.3.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Drupal 7 core does not include Twig and therefore is not affected.
Introduction
Drupal has released a security update to address a Twig critical vulnerability. Drupal uses the Twig third-party library for content templating and sanitisation. This vulnerability could lead to potential unauthorised information disclosure. An attacker could exploit this vulnerability to take control of an affected system.
The vulnerability is mitigated by the fact that an exploit is only possible in Drupal core with a restricted access administrative permission.
Remediation advice
Affected organisations are encouraged to review Drupal security advisory SA-CORE-2022-016 and apply the relevant update.
Definitive source of threat updates
Last edited: 5 October 2022 4:36 pm