Drupal core - Critical - Cross Site Request Forgery - SA-CORE-2020-004
https://www.drupal.org/sa-core-2020-004Project: Drupal core (
https://www.drupal.org/project/drupal)Date: 2020-June-17Security risk: Critical 15∕25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross Site Request ForgeryCVE IDs: CVE-2020-13663Description: The Drupal core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.Solution: If you are using Drupal 7.x, upgrade to Drupal 7.72 (
https://www.drupal.org/project/drupal/releases/7.72).
If you are using Drupal 8.8.x, upgrade to Drupal 8.8.8 (
https://www.drupal.org/project/drupal/releases/8.8.8).
If you are using Drupal 8.9.x, upgrade to Drupal 8.9.1 (
https://www.drupal.org/project/drupal/releases/8.9.1).
If you are using Drupal 9.0.x, upgrade to Drupal 9.0.1 (
https://www.drupal.org/project/drupal/releases/9.0.1).
Versions of Drupal 8 prior to 8.8.x are end-of-life and do not receive security coverage. Sites on 8.7.x or earlier should update to 8.8.8.Reported By: Samuel Mortenson (
https://www.drupal.org/user/2582268) of the Drupal Security Team
Dor Tumarkin (
https://www.drupal.org/user/3648639)
Fixed By: Greg Knaddison (
https://www.drupal.org/user/36762) of the Drupal Security Team
Samuel Mortenson (
https://www.drupal.org/user/2582268) of the Drupal Security Team
Jess (
https://www.drupal.org/user/65776) of the Drupal Security Team
Lee Rowlands (
https://www.drupal.org/user/395439) of the Drupal Security Team
Angie Byron (
https://www.drupal.org/user/24967) of the Drupal Security Team
Peter Wolanin (
https://www.drupal.org/user/49851) of the Drupal Security Team
Daniel Wehner (
https://www.drupal.org/user/99340)
Dor Tumarkin (
https://www.drupal.org/user/3648639)
Drew Webber (
https://www.drupal.org/user/255969) of the Drupal Security Team
Alex Pott (
https://www.drupal.org/user/157725) of the Drupal Security Team
David Snopek (
https://www.drupal.org/user/266527) of the Drupal Security Team