Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075
  • Date: Wed, 8 Jul 2026 17:17:42 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/IADXOD3T7OHKV4WA4L4NSECPN7PTCI3Y/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=PN8qiNj7; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=SdlMlK4c; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=S9UZqSuO; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp1.osuosl.org B23B982D0F
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org 09D85400AD
  • Dmarc-filter: OpenDMARC Filter v1.4.2 smtp2.osuosl.org 09D85400AD
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-075

Project: UI Patterns (SDC in Drupal UI) [1]
Date: 2026-July-08
Security risk: *Moderately critical* 14 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross site scripting

Affected versions: <2.0.17
CVE IDs: CVE-2026-15084
Description: 
This module enables you to use Single Directory Components in site building
(views, field formatters, blocks, layouts) and it improves the Developer
Experience (DX) with SDC.

The module doesn't sufficiently sanitize the markup passed to components
under certain scenarios.

This vulnerability is mitigated by the fact that an attacker must be able to
create or update content rendered by UI Patterns.

Solution: 
Install the latest version:

* If you use the UI Patterns module on version 2, upgrade to UI Patterns
2.0.17 [3]

Reported By: 
* Hervé Donner (herved) [4]

Fixed By: 
* Florent Torregrosa (grimreaper) [5]
* Hervé Donner (herved) [6]
* Mikael Meulle (just_like_good_vibes) [7]
* Pierre Dureau (pdureau) [8]

Coordinated By: 
* Neil Drumm (drumm) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Juraj Nemec (poker10) [11] of the Drupal Security Team
* Dave Long (longwave) [12] of the Drupal Security Team

Security
issue: 
https://git.drupalcode.org/security/185300-ui_patterns-security/-/work_items/1
[13]
------------------------------------------------------------------------------
Contribution record [14]

[1] https://www.drupal.org/project/ui_patterns
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ui_patterns/releases/2.0.17
[4] https://www.drupal.org/u/herved
[5] https://www.drupal.org/u/grimreaper
[6] https://www.drupal.org/u/herved
[7] https://www.drupal.org/u/just_like_good_vibes
[8] https://www.drupal.org/u/pdureau
[9] https://www.drupal.org/u/drumm
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/poker10
[12] https://www.drupal.org/u/longwave
[13] https://git.drupalcode.org/security/185300-ui_patterns-security/-/work_items/1
[14] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3608032

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075, security-news, 08.07.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang