Skip to main content

Drupal Releases Security Update

Security update addresses multiple vulnerabilities affecting the Twig library

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security update addresses multiple vulnerabilities affecting the Twig library


Affected platforms

The following platforms are known to be affected:

Threat details

Prior versions of Drupal

All versions of Drupal 9 prior to 9.3.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.

Drupal 7 core does not include Twig and therefore is not affected.


Introduction

Drupal has released a security update to address a Twig critical vulnerability. Drupal uses the Twig third-party library for content templating and sanitisation. This vulnerability could lead to potential unauthorised information disclosure. An attacker could exploit this vulnerability to take control of an affected system. 

The vulnerability is mitigated by the fact that an exploit is only possible in Drupal core with a restricted access administrative permission.


Remediation advice

Affected organisations are encouraged to review Drupal security advisory SA-CORE-2022-016 and apply the relevant update.


Definitive source of threat updates


Last edited: 5 October 2022 4:36 pm