|
|
Subscribe / Log in / New account

Arch Linux alert ASA-202106-35 (drupal)

From:  Santiago Torres-Arias via arch-security <arch-security@lists.archlinux.org>
To:  Archlinux security <arch-security@archlinux.org>
Subject:  [ASA-202106-35] drupal: cross-site scripting
Date:  Thu, 17 Jun 2021 12:25:03 -0400
Message-ID:  <YMt3XzUBX536BtcE@LykOS.localdomain>
Cc:  Santiago Torres-Arias <santiago@archlinux.org>

Arch Linux Security Advisory ASA-202106-35 ========================================== Severity: High Date : 2021-06-15 CVE-ID : CVE-2021-33829 Package : drupal Type : cross-site scripting Remote : Yes Link : https://security.archlinux.org/AVG-2069 Summary ======= The package drupal before version 9.1.10-1 is vulnerable to cross-site scripting. Resolution ========== Upgrade to 9.1.10-1. # pacman -Syu "drupal>=9.1.10-1" The problem has been fixed upstream in version 9.1.10. Workaround ========== None. Description =========== Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to a cross-site scripting (XSS) attack. CKEditor 4.16.1 and later, as bundled with Drupal 9.1.9, include the fix. Impact ====== A remote attacker could execute arbitrary JavaScript code through cross-site scripting using crafted HTML code. References ========== https://www.drupal.org/sa-core-2021-003 https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibil... https://security.archlinux.org/CVE-2021-33829


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds