- Third Party Libraries
- Multiple vulnerabilities
- Backdrop Core 1.14.x versions prior to 1.14.2
- Backdrop Core 1.13.x versions prior to 1.13.5
The Backdrop CMS project uses the third-party library Archive_Tar, which has released a security update that impacts some Backdrop configurations.
Multiple vulnerabilities are possible if Backdrop is configured to allow .tar
, .tar.gz
, .bz2
or .tlz
file uploads, and processes them.
The latest versions of Backdrop update Archive_Tar
to 1.4.9 to mitigate these file processing vulnerabilities.
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.14.2 release page. See the update instructions, if needed.
- Lee Rowlands of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Sam Becker
- Jasper Mattsson
- David Rothstein of the Drupal Security Team
- michieltcs
- Ayesh Karunaratne
- Alex Pott of the Drupal Security Team
- Jess of the Drupal Security Team
- Samuel Mortenson of the Drupal Security Team
- Vijaya Chandran Mani
- Drew Webber of the Drupal Security Team
- Jen Lampton of the Backdrop CMS Security Team
- Nate Lampton of the Backdrop CMS Security Team
- Jen Lampton of the Backdrop CMS Security Team
- Gregory Nestas of the Backdrop CMS Security Team