Drupal.org Updates Handling of Drupal Core Issues

Data Securty, Cyber Security

Drupal.org, the official website for the Drupal content management system, has announced a significant change in how certain risk-level issues within the Drupal core will be handled. Effective immediately, Drupal core issues reported to the Security Team with risk levels categorized as "Not Critical," "Less Critical," or "Moderately Critical" will be treated as bugs in the public issue queue rather than private security issues requiring a security advisory and Common Vulnerabilities and Exposures (CVE) identification. This adjustment aims to expedite the resolution of these issues by utilizing public issue queues.

The decision to revise the handling of Drupal core issues stems from the desire to address and fix such issues more swiftly, leveraging the collaborative efforts of the broader Drupal community. The Security Team will exercise its discretion to determine whether certain issues can be addressed publicly, considering factors such as the risk score, severity of impact, exploit difficulty, and any additional mitigating factors.

Despite this change, the Drupal Security Team encourages security researchers to initiate the reporting process by filing private issues, which may later be transitioned to public status. Additionally, there may be instances where the Security Team decides to convert a public issue into a private one when necessary.

Drupal core issues carrying a risk level of "Critical" or "Highly Critical" will remain treated as private security issues, ensuring the appropriate level of confidentiality and urgency. Furthermore, some lower-risk issues may still be handled privately at the discretion of the Security Team based on their potential impact.

To learn more about the updated procedures for handling Drupal core issues, interested individuals can visit the official Drupal.org website.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please let us know in the comments below and we will try to address the issue as best we can.

Advertisement Here

Upcoming Events

Latest Opportunities

Advertisement Here

Call for Support