it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Drupal core - Moderately critical - Third-party library - SA-CORE-2020-001
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Drupal core - Moderately critical - Third-party library - SA-CORE-2020-001
- Date: Wed, 18 Mar 2020 19:56:20 +0000 (UTC)
- List-archive: <http://lists.drupal.org/pipermail/security-news/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-core-2020-001
Project: Drupal core [1]
Version: 8.8.x-dev8.7.x-dev
Date: 2020-March-18
Security risk: *Moderately critical* 13∕25
AC:Complex/A:User/CI:Some/II:Some/E:Proof/TD:Default [2]
Vulnerability: Third-party library
Description:
The Drupal project uses the third-party library CKEditor [3], which has
released a security improvement [4] that is needed to protect some Drupal
configurations.
Vulnerabilities are possible if Drupal is configured to use the WYSIWYG
CKEditor for your site’s users. When multiple people can edit content, the
vulnerability can be used to execute XSS attacks against other people,
including site admins with more access.
The latest versions of Drupal update CKEditor to 4.14 to mitigate the
vulnerabilities.
Solution:
Install the latest version:
* If you are using Drupal 8.8.x, upgrade to Drupal 8.8.4 [5].
* If you are using Drupal 8.7.x, upgrade to Drupal 8.7.12 [6].
Versions of Drupal 8 prior to 8.7.x have reached end-of-life and do not
receive security coverage.
The CKEditor module can also be disabled to mitigate the vulnerability until
the site is updated.
.... Note for Drupal 7 users
Drupal 7 core is not affected by this release; however, users who have
installed the third-party CKEditor library (for example, with a contributed
module) should ensure that the downloaded library is updated to CKEditor 4.14
or higher, or that CDN URLs point to a version of CKEditor 4.14 or higher.
Disabling all WYSIWYG modules can mitigate the vulnerability until the site
is updated.
[1] https://www.drupal.org/project/drupal
[2] https://www.drupal.org/security-team/risk-levels
[3] https://github.com/ckeditor/ckeditor4
[4]
https://ckeditor.com/blog/CKEditor-4.14-with-Paste-from-LibreOffice-released/#security-issues-fixed
[5] https://www.drupal.org/project/drupal/releases/8.8.4
[6] https://www.drupal.org/project/drupal/releases/8.7.12
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecNots] [Security-news] Drupal core - Moderately critical - Third-party library - SA-CORE-2020-001, security-news, 18.03.2020
Archiv bereitgestellt durch MHonArc 2.6.19.