[SECURITY-L] [Security-news] Off Cycle Drupal Core Security Release - PSA-2021-05-25

CSIRT Unicamp security em unicamp.br
Terça Maio 25 15:09:49 -03 2021


View online: https://www.drupal.org/psa-2021-05-25

Date: 2021-May-25
Description:
There will be a security release of Drupal Core 8.9.x, and 9.1.x on May
26th,
2021 between 16:00 - 18:00 UTC. This Public Service Advisory is to notify
that the Drupal core release is outside of the regular schedule of security
releases. For all security updates, the Drupal Security Team urges you to
reserve time for core updates at that time because there is some risk that
exploits might be developed within hours or days. Security release
announcements will appear on the Drupal.org security advisory page.

The security risk of the advisory is currently rated as Moderately Critical.
This is not a mass-exploitable vulnerability as far as the security team is
currently aware.

Given that this is a moderately critical vulnerability and is not believed
to
be mass exploitable it is not covered by Drupal Steward partners. [1]


[1] https://www.drupal.org/drupal-security-team/steward

_______________________________________________
Security-news mailing list
Security-news em drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


===
Computer Security Incident Response Team - CSIRT
Universidade Estadual de Campinas - Unicamp
Centro de Computacao - CCUEC
GnuPG Public Key: http://www.security.unicamp.br/security.asc [^]
Contato: +55 19 3521-2289 ou INOC-DBA: 1251*830
-------------- Próxima Parte ----------
Um anexo em HTML foi limpo...
URL: <http://www.listas.unicamp.br/pipermail/security-l/attachments/20210525/3a6146f0/attachment.html>


Mais detalhes sobre a lista de discussão SECURITY-L