Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data. https://www.drupal.org/sa-core-2022-003
Created drupal7 tracking bugs for this issue: Affects: epel-all [bug 2055472] Affects: fedora-all [bug 2055473] Created drupal8 tracking bugs for this issue: Affects: fedora-all [bug 2055474]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.