Drupal has released security advisories to address cross site scripting and open redirect vulnerabilities in the jQuery library and the “drupal_goto” function of Drupal Core. A remote attacker may send specially crafted HTTP requests to exploit the vulnerabilities.
Please note that Drupal 8 prior to version 8.7 has reached its End-Of-Life (EOL) in December 2019. No security updates will be provided after that. Users should arrange upgrading the Drupal to supported versions or migrating to other supported technology.
A successful attack could lead to cross site scripting on an affected system or redirecting users to malicious websites.
The product vendor has released patches to address the issues.
https://www.drupal.org/sa-core-2020-002
https://www.drupal.org/sa-core-2020-003
https://www.drupal.org/core/release-cycle-overview
https://www.us-cert.gov/ncas/current-activity/2020/05/21/drupal-releases-security-updates
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11022
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11023