🕵️ SicherheitslückenCVE-2026-65017 | Apache Airflow Config API information disclosure(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-67587 | Apache Airflow deserialization(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-54183 | Apache Airflow information disclosure (EUVD-2026-57310)(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-59242 | Apache Airflow XCom deserialize endpoint deserialization(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-67260 | Apache Airflow Scheduler next_kwargs deserialization(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-65017 | Apache Airflow Config API information disclosure(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-67587 | Apache Airflow deserialization(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-54183 | Apache Airflow information disclosure (EUVD-2026-57310)(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-59242 | Apache Airflow XCom deserialize endpoint deserialization(17.09.2026 um 05:49 Uhr)
🕵️ SicherheitslückenCVE-2026-67260 | Apache Airflow Scheduler next_kwargs deserialization(17.09.2026 um 05:49 Uhr)
📰 IT Security Nachrichten 🕛 vor 3 Jahren 2 Min Lesezeit SECURITY-FEED
0

Drupal core - Moderately critical - Access bypass - SA-CORE-2023-005

↗ Quelle (drupal.org)
🗣️ Stimme:
Project: 
Vulnerability: 
Access bypass
Description: 

The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to.


Some sites may require configuration changes following this security release. Review the release notes for your Drupal version if you have issues accessing private files after updating.


This advisory is covered by .

  • If you are using Drupal 9.5, update to .

  • If you are using Drupal 7, update to .

  • Reported By: 

    • of the Drupal Security Team

    • of the Drupal Security Team

    • of the Drupal Security Team

    • of the Drupal Security Team


    • of the Drupal Security Team

    • , provisional member of the Drupal Security Team

    • of the Drupal Security Team

    • of the Drupal Security Team

    • Neil Drumm of the Drupal Security Team

    Vollständiges Original-Advisory
    Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf drupal.org.
    ↗ Original-Artikel auf drupal.org lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:
    Community Threat-Level Barometer
    Live Votum

    Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

    Noch keine Stimmen — schätze das Risiko als Erster ein.

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    8 Quellen
    CVE-2026-65017 | Apache Airflow Config API information disclosure
    2 Quellen
    CVE-2026-18708 | MongoDB up to 7.0.39/8.0.28/8.3.7 JavaScript Scripting Engine code injection
    2 Quellen
    CVE-2026-18706 | MongoDB Server up to 8.3.7 GraphLookup Aggregation Stage use after free
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten Drupal core - Moderately critical - Access bypass - SA-CORE-2023-005

    Thematisch verwandte Begriffe: Drupal, core, Moderately, critical · 6 Treffer

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...