Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Security advisory coverage removed - PSA-2026-07-22

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Security advisory coverage removed - PSA-2026-07-22


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Security advisory coverage removed - PSA-2026-07-22
  • Date: Wed, 22 Jul 2026 17:59:58 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/JYZEJMRFIFF7OMJ5IANZTRIZZ4UI3YY3/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=U0NzNzd1; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=RQXAALqe; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="DlOn/ITC"; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org B17FD4085C
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 8A236605D9
  • Dmarc-filter: OpenDMARC Filter v1.4.2 smtp3.osuosl.org 8A236605D9
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/psa-2026-07-22

Date: 2026-July-22
Description: 
QA Accounts [1] enables you to login to a Drupal site using a well known
username/password combination. When 1.0 was released, it also was marked for
security coverage. The module prioritizes ease of use rather than security
and is only intended to be used on sites that are not accessible on the
internet (e.g. behind firewall or other protection). The maintainers are
choosing to remove security coverage.

Solution: 
Ensure qa_accounts is not enabled on any publicly available site.

Reported By: 
* Jordan Barnes (j-barnes) [2]

Fixed By: 
* Jakob P (japerry) [3]

------------------------------------------------------------------------------
Contribution record [4]

[1] https://www.drupal.org/project/qa_accounts
[2] https://www.drupal.org/u/j-barnes
[3] https://www.drupal.org/u/japerry
[4] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3612108

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Security advisory coverage removed - PSA-2026-07-22, security-news, 22.07.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang