Description
Drupal Core is prone to multiple vulnerabilities, including session hijacking and denial of service vulnerabilities. Exploiting these issues could allow an attacker to access another user's session or to cause the affected website to consume memory and CPU resources, thus denying service to legitimate users. Drupal Core versions 7.x ranging from 7.0 and up to and including 7.33 are vulnerable.
Remediation
Update to Drupal Core version 7.34 or latest
References
Related Vulnerabilities
MySQL CVE-2016-3518 Vulnerability (CVE-2016-3518)
Python URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-28861)
WordPress Plugin Duplicate Post Cross-Site Scripting (2.6)
WordPress Plugin WP Private Message Insecure Direct Object Reference (1.0.5)
Atlassian Jira CVE-2020-14167 Vulnerability (CVE-2020-14167)