Important Security Update for Drupal
Team Host.it 2 min read
Content
The bug, which can have very serious consequences, has been named " Drupalgeddon2 ". Specifically, this flaw allows anyone to initiate remote code execution without any form of authentication causing the website to be completely compromised. The only information needed to exploit the security flaw is knowing the site's URL.
HOW TO APPLY THE SECURITY PATCH TO SECURE YOUR WEBSITE
We therefore invite you to follow the guidelines below and immediately update the Drupal CMS version:
Drupal 7.x: Upgrade to Drupal 7.58. If you cannot perform an immediate update you can apply this patch to fix the vulnerability.
Drupal 8.5.x: Upgrade to Drupal 8.5.1. Again, you can apply a patch before updating.
Drupal versions 8.3.x and 8.4.x are no longer supported and, for this reason, security fixes are no longer released. However, given the severity of the flaw, the CMS developers still released the patch even for minor versions before updating to version 8.5.0 (currently recommended version). If the version of Drupal used is:
Drupal 8.3.x: You need to upgrade to version 8.3.9 and apply this patch
Drupal 8.4.x: You need to upgrade to version 8.4.6 and apply this patch
The security bug also impacts versions of Drupal 8.2.x and earlier, which we remind you are no longer supported:
Drupal 8.2.x: You need to update to a newer version and then follow the instructions above.
Drupal 6 EOL (End Of Life): To support this version you need to contact D6LTS vendor
For more information regarding this security flaw and the related patches, we invite you to read the developers' announcement published on the official Drupal website.
Before any update/modification on the website, we advise you to check that the templates and components are compatible with the new installation and to perform a preventive data backup in order to immediately restore the contents of the website in the event that the operation is not successful.
We remind you that our technical staff is available for further clarifications by opening a ticket after logging in to the host.it Customer Area.
At Host, we strongly believe in the role of the hosting provider as a partner in our customers' business. All our customers who use Drupal have been notified via email and, through this article, we want to make public our commitment to keeping your websites safe.
Finally, we remind you that update procedures are necessary to ensure the success of your online business!
Domains
Register or transfer your domain
.it, .com, .eu extensions and managed DNS. Fast activation plus support for pointing and email.
Related articles
From the blog
From the archive