Hacker News new | ask | show | jobs
by pearjuice 4263 days ago
Ah, must have overlooked the months. Makes me wonder why they left this in the wild for a month and now suddenly put thousands of installations at risk.
1 comments

> now suddenly put thousands of installations at risk

There's a solution that goes with the advisory. You cannot provide a patch without putting sites at risk.

Furthermore, the vulnerability was present since the Drupal 7.0 release, several years ago. There were no exploits seen in the wild. What are a few weeks then?

The team decided that speed to patch sites asap _after_ release of the information was critical. This is the reason why it was released after a pre-announcement and after a conference tying up most stakeholders.