Vulnerabilities in Drupal 8.9, 9.1, and 9.2

Published on 19 Nov 2021

Updated on 19 Nov 2021

Drupal, a Content Management Software (CMS) used to manage content and host websites, has released security updates to address two vulnerabilities (CVE-2021-41164 and CVE-2021-41165). The vulnerabilities can be exploited if the CMS is configured to allow the use of the CKEditor library. 

Successful exploitation of the vulnerabilities could allow an attacker to execute code and take control of an affected system.

Users and System Administrators are advised to patch the following versions on affected servers immediately:
•            If you are using Drupal 9.2, update to Drupal 9.2.9.
•            If you are using Drupal 9.1, update to Drupal 9.1.14.
•            If you are using Drupal 8.9, update to Drupal 8.9.20.

More information is available here:
https://www.drupal.org/sa-core-2021-011