The Drupal security team has issued a “moderately critical” advisory to draw attention to major flaws in a third-party library, warning that hackers might use the flaws to remotely take control of Drupal-powered sites.
Guzzle, a third-party library used by Drupal to handle HTTP requests and answers to external services, was detected and fixed with the vulnerabilities CVE-2022-31042 and CVE-2022-31043. Read More…