[Security-news] Drupal core - Moderately critical - Third-party library - SA-CORE-2020-001
security-news at drupal.org
security-news at drupal.org
Wed Mar 18 19:56:20 UTC 2020
View online: https://www.drupal.org/sa-core-2020-001
Project: Drupal core [1]
Version: 8.8.x-dev8.7.x-dev
Date: 2020-March-18
Security risk: *Moderately critical* 13∕25
AC:Complex/A:User/CI:Some/II:Some/E:Proof/TD:Default [2]
Vulnerability: Third-party library
Description:
The Drupal project uses the third-party library CKEditor [3], which has
released a security improvement [4] that is needed to protect some Drupal
configurations.
Vulnerabilities are possible if Drupal is configured to use the WYSIWYG
CKEditor for your site’s users. When multiple people can edit content, the
vulnerability can be used to execute XSS attacks against other people,
including site admins with more access.
The latest versions of Drupal update CKEditor to 4.14 to mitigate the
vulnerabilities.
Solution:
Install the latest version:
* If you are using Drupal 8.8.x, upgrade to Drupal 8.8.4 [5].
* If you are using Drupal 8.7.x, upgrade to Drupal 8.7.12 [6].
Versions of Drupal 8 prior to 8.7.x have reached end-of-life and do not
receive security coverage.
The CKEditor module can also be disabled to mitigate the vulnerability until
the site is updated.
.... Note for Drupal 7 users
Drupal 7 core is not affected by this release; however, users who have
installed the third-party CKEditor library (for example, with a contributed
module) should ensure that the downloaded library is updated to CKEditor 4.14
or higher, or that CDN URLs point to a version of CKEditor 4.14 or higher.
Disabling all WYSIWYG modules can mitigate the vulnerability until the site
is updated.
[1] https://www.drupal.org/project/drupal
[2] https://www.drupal.org/security-team/risk-levels
[3] https://github.com/ckeditor/ckeditor4
[4]
https://ckeditor.com/blog/CKEditor-4.14-with-Paste-from-LibreOffice-released/#security-issues-fixed
[5] https://www.drupal.org/project/drupal/releases/8.8.4
[6] https://www.drupal.org/project/drupal/releases/8.7.12
More information about the Security-news
mailing list