CVE-2022-25276

NameCVE-2022-25276
DescriptionThe Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
drupal7source(unstable)(not affected)

Notes

- drupal7 <not-affected> (Only affects Drupal 8 and 9)
https://www.drupal.org/sa-core-2022-015

Search for package or bug name: Reporting problems