Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Drupal core - Moderately critical - Defacement - SA-CORE-2025-007

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Drupal core - Moderately critical - Defacement - SA-CORE-2025-007


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Drupal core - Moderately critical - Defacement - SA-CORE-2025-007
  • Date: Thu, 13 Nov 2025 00:13:59 +0000 (UTC)
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Vge0zjfJ; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org EE96C40FCC
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp1.osuosl.org 9860282EB4
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-core-2025-007

Project: Drupal core [1]
Date: 2025-May-29
Security risk: *Moderately critical* 10 ∕ 25
AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:All [2]
Vulnerability: Defacement

Affected versions: >= 8.0.0 < 10.4.9 || >= 10.5.0 < 10.5.6 || >= 11.0.0 <
11.1.9 || >= 11.2.0 < 11.2.8
CVE IDs: CVE-2025-13082
Description: 
By generating and tricking a user into visiting a malicious URL, an attacker
can perform site defacement.

The defacement is not stored and is only present when the URL has been
crafted for that purpose. Only the defacement is present, so no other site
content (such as branding) is rendered.

Solution: 
Install the latest version:

* If you are using Drupal 10.4, update to Drupal 10.4.9 [3].
* If you are using Drupal 10.5, update to Drupal 10.5.6 [4].
* If you are using Drupal 11.1, update to Drupal 11.1.9 [5].
* If you are using Drupal 11.2, update to Drupal 11.2.8 [6].

Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive
security coverage. (Drupal 8 [7] and Drupal 9 [8] have both reached
end-of-life.)

Reported By: 
* Kevin Quillen (kevinquillen) [9]

Fixed By: 
* Benji Fisher (benjifisher) [10] of the Drupal Security Team
* Neil Drumm (drumm) [11] of the Drupal Security Team
* Greg Knaddison (greggles) [12] of the Drupal Security Team
* Lee Rowlands (larowlan) [13] of the Drupal Security Team
* Drew Webber (mcdruid) [14] of the Drupal Security Team
* Mingsong (mingsong) [15], provisional member of the Drupal Security Team
* Juraj Nemec (poker10) [16] of the Drupal Security Team
* Ra Mänd (ram4nd) [17], provisional member of the Drupal Security Team
* Jess (xjm) [18] of the Drupal Security Team

Coordinated By: 
* catch (catch) [19] of the Drupal Security Team
* Lee Rowlands (larowlan) [20] of the Drupal Security Team
* Dave Long (longwave) [21] of the Drupal Security Team
* Juraj Nemec (poker10) [22] of the Drupal Security Team

Security
issue: https://git.drupalcode.org/security/7-drupal-security/-/issues/1 [23]
------------------------------------------------------------------------------
Contribution record [24]

[1] https://www.drupal.org/project/drupal
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/drupal/releases/10.4.9
[4] https://www.drupal.org/project/drupal/releases/10.5.6
[5] https://www.drupal.org/project/drupal/releases/11.1.9
[6] https://www.drupal.org/project/drupal/releases/11.2.8
[7] https://www.drupal.org/psa-2021-06-29
[8] https://www.drupal.org/psa-2023-11-01
[9] https://www.drupal.org/u/kevinquillen
[10] https://www.drupal.org/u/benjifisher
[11] https://www.drupal.org/u/drumm
[12] https://www.drupal.org/u/greggles
[13] https://www.drupal.org/u/larowlan
[14] https://www.drupal.org/u/mcdruid
[15] https://www.drupal.org/u/mingsong
[16] https://www.drupal.org/u/poker10
[17] https://www.drupal.org/u/ram4nd
[18] https://www.drupal.org/u/xjm
[19] https://www.drupal.org/u/catch
[20] https://www.drupal.org/u/larowlan
[21] https://www.drupal.org/u/longwave
[22] https://www.drupal.org/u/poker10
[23] https://git.drupalcode.org/security/7-drupal-security/-/issues/1
[24] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3527346

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] Drupal core - Moderately critical - Defacement - SA-CORE-2025-007, security-news, 13.11.2025

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang