[IS&T Security-FYI] Drupal security advisory released October 17

Garry Zacheiss zacheiss at mit.edu
Thu Oct 18 10:22:47 EDT 2018


Good morning,

On October 17, several significant security issues in the Drupal content management system were publicly announced:

https://www.drupal.org/sa-core-2018-006

Drupal is a widely deployed technology at MIT. Information Systems & Technology (IS&T), beginning yesterday evening, has taken steps to address these issues.


  *   Web sites deployed via IS&T’s Drupal Cloud service were patched on October 17 and site administrators were notified via email.  No additional action is required on the part of Drupal Cloud site administrators.



  *   Drupal sites hosted via IS&T managed server hosting are likewise being patched.  This work is in progress and IS&T will coordinate with hosting clients as needed to discuss specific details regarding these sites.

Drupal sites at MIT not managed by IS&T should be updated promptly, and we encourage you to follow up with your support provider regarding this issue as soon as possible.

If you have any questions or require assistance, please contact the IS&T Service Desk<mailto:servicedesk at mit.edu>.


Sincerely,

Garry



Garry Zacheiss

Director, Platform & Systems Integration

MIT Information Systems & Technology

zacheiss at mit.edu<mailto:zacheiss at mit.edu> // +1 617 253 7675

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.mit.edu/pipermail/ist-security-fyi/attachments/20181018/9942f6dd/attachment.html


More information about the ist-security-fyi mailing list