it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075
- Date: Wed, 11 Dec 2024 17:46:01 +0000 (UTC)
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=HCa0yXQd; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; dmarc=pass (policy=none) header.from=drupal.org
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org 09F69417E2
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org C5641610A2
- List-archive: <http://lists.drupal.org/pipermail/security-news/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2024-075
Project: Allow All File Extensions for file fields [1]
Date: 2024-December-11
Security risk: *Critical* 18 ∕ 25
AC:Basic/A:User/CI:All/II:All/E:Theoretical/TD:All [2]
Vulnerability: Unsupported
Affected versions: *
Description:
The security team is marking this project unsupported. There is a known
security issue with the project that has not been fixed by the maintainer. If
you would like to maintain this project, please read:
https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...
[3]
Solution:
If you use this project, you should uninstall it. To take over
maintainership, please read
https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...
[4]
[1] https://www.drupal.org/project/all_extensions
[2] https://www.drupal.org/security-team/risk-levels
[3]
https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-maintainer-of-a-project-that-is-unsupported-for-security-reasons
[4]
https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-maintainer-of-a-project-that-is-unsupported-for-security-reasons
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecNots] [Security-news] Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075, security-news, 11.12.2024
Archiv bereitgestellt durch MHonArc 2.6.19+.