
10/16/2014 · John Graham-Cumming
What this post added
This post details the immediate mitigation of a critical SQL injection vulnerability (SA-CORE-2014-005) in Drupal 7 by updating Cloudflare's Web Application Firewall (WAF) rules. It specifically mentions Rule D0002 as providing protection and instructs users to enable the 'CloudFlare Drupal' ruleset if not already active. The post also strongly advises users to upgrade to the safe version of Drupal (7.32) or apply the patch, and provides an update on the severity of the vulnerability based on a Drupal Security Team PSA, indicating that sites not patched before a specific date should be assumed compromised.