Drupal 8 uses the third-party PHP library Guzzle for making server-side HTTP requests. An attacker could provide a proxy server that Guzzle will use. The details of this are explained at https://httpoxy.org/.

Part of security release SA-CORE-2016-003

This vulnerability affects the following application versions:

  • Drupal 8.0.0
  • Drupal 8.0.1
  • Drupal 8.0.2
  • Drupal 8.0.3
  • Drupal 8.0.4
  • Drupal 8.0.5
  • Drupal 8.0.6
  • Drupal 8.1.0
  • Drupal 8.1.1
  • Drupal 8.1.2
  • Drupal 8.1.3
  • Drupal 8.1.4
  • Drupal 8.1.5
  • Drupal 8.1.6

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *