On May 8, 2025, Drupal issued security advisories to address vulnerabilities across various products. The updates pertained to two key areas:
-
Enterprise MFA – TFA for Drupal
- Affected versions include those prior to 4.7.0, as well as versions 5.0.0 up to earlier than 5.2.0.
- Restrict Path by IP
- This issue affects versions prior to 1.3.0.
The Cyber Center urged users and administrators to review the provided web links and apply necessary updates to ensure security.
For detailed information about the specifics of these vulnerabilities and the steps for mitigation, users were encouraged to follow the links shared in the advisories. Implementing these updates is crucial to maintaining the security of Drupal installations and protecting against potential threats.