- Backdrop core versions prior to 1.12.1 and 1.11.5
Backdrop core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Backdrop configurations. Refer to CVE-2018-1000888 for details.
Another SA was released today, see also:
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.12.1 release page. See the update instructions, if needed.
- Nate Lampton of the Backdrop CMS Security Team
- Jess of the Drupal Security Team
- Ayesh Karunaratne
- michieltcs
- Lee Rowlands of the Drupal Security Team
- Alex Pott of the Drupal Security Team
- Nate Lampton of the Backdrop CMS Security Team
- Jen Lampton of the Backdrop CMS Security Team
- Tim Erickson