Security Alert (A21-07-15): Vulnerability in Drupal
23 July 2021
Drupal has released a security advisory to address a vulnerability in the pear Archive_Tar library. Systems deployed with contrib or custom code that use the library to extract tar archives are affected. A remote attacker may upload a maliciously crafted file to a vulnerable system to exploit the vulnerability.
Please note that Drupal 8 prior to version 8.9.x and Drupal 9 prior to version 9.1.x have reached End-Of-Life (EOL). No security updates will be provided after that. Users should arrange upgrading the Drupal to supported versions or migrating to other supported technology.
Drupal version 7.x
Drupal version 8.9.x
Drupal version 9.1.x
Drupal version 9.2.x
Successful exploitation could allow attacker to take control of an affected system.
The product vendor has released patches to address the issues.