Description
Drupal Core is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. Drupal Core version 8.9.0 is vulnerable.
Remediation
Update to Drupal Core version 8.9.1 or latest
References
Related Vulnerabilities
Drupal Core 8.9.x Information Disclosure (8.9.0 - 8.9.5)
WordPress Plugin Gallery-Video Gallery and Youtube Gallery SQL Injection (2.0.9)
WordPress Plugin Subscriber by BestWebSoft Cross-Site Scripting (1.3.4)
WordPress Plugin Keyword Strategy Internal Links Multiple Cross-Site Scripting Vulnerabilities (2.0)