Skip to content
This repository was archived by the owner on Aug 8, 2024. It is now read-only.

Update to Drupal 9.5.7. For more information, see https://www.drupal.org/project/drupal/releases/9.5.7 - #428

Closed
pantheon-upstream wants to merge 1 commit into
default-9.xfrom
update-9.5.7
Closed

Update to Drupal 9.5.7. For more information, see https://www.drupal.org/project/drupal/releases/9.5.7#428
pantheon-upstream wants to merge 1 commit into
default-9.xfrom
update-9.5.7

Conversation

@pantheon-upstream

Copy link
Copy Markdown

Update from Drupal 9.1.0 to Drupal 9.5.7.

This is experimental. Do not merge.

@guardrails

guardrails Bot commented Mar 24, 2023

Copy link
Copy Markdown

⚠️ We detected 21 security issues in this pull request:

Hard-Coded Secrets (1)
Docs Details
💡 Title: Secret Keyword, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/user/config/install/user.mail.yml#L34

More info on how to fix Hard-Coded Secrets in General.


Insecure Use of Regular Expressions (4)
Docs Details
💡 Title: Regex DOS (ReDOS), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/misc/position.es6.js#L30
💡 Title: Regex DOS (ReDOS), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/misc/position.js#L13
💡 Title: Regex DOS (ReDOS), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/scripts/js/ckeditor5-types-documentation.js#L30
💡 Title: Regex DOS (ReDOS), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/scripts/js/vendor-update.js#L34

More info on how to fix Insecure Use of Regular Expressions in JavaScript.


Information Disclosure (1)
Docs Details
💡 Title: Use of phpinfo(), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/system/src/Controller/SystemInfoController.php#L62

More info on how to fix Information Disclosure in PHP.


Insecure Processing of Data (3)
Docs Details
💡 Title: Insecure HTTP redirect, Severity: Low
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/.ht.router.php#L29
💡 Title: Unescaped user input in HTML, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/ckeditor5/js/ckeditor5.es6.js#L652
💡 Title: Unescaped user input in HTML, Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/ckeditor5/js/ckeditor5.js#L291

More info on how to fix Insecure Processing of Data in PHP and JavaScript.


Insecure Use of Dangerous Function (6)
Docs Details
💡 Title: Dynamic evaluation of untrusted input (Frontend), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/ckeditor5/js/ckeditor5.admin.es6.js#L328
💡 Title: Dynamic evaluation of untrusted input (Frontend), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/ckeditor5/js/ckeditor5.admin.es6.js#L737
💡 Title: Dynamic evaluation of untrusted input (Frontend), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/ckeditor5/js/ckeditor5.admin.js#L184
💡 Title: Dynamic evaluation of untrusted input (Frontend), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/modules/ckeditor5/js/ckeditor5.admin.js#L386
💡 Title: Dynamic evaluation of untrusted input (Frontend), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/themes/olivero/js/second-level-navigation.es6.js#L81
💡 Title: Dynamic evaluation of untrusted input (Frontend), Severity: Medium
https://github.com/pantheon-systems/drops-8/blob/e975322f0b996d7f39a7091eac35c3820981c08a/core/themes/olivero/js/second-level-navigation.js#L38

More info on how to fix Insecure Use of Dangerous Function in JavaScript.


Vulnerable Libraries (6)
Severity Details
Medium pkg:npm/jquery-form@4.3.0@4.3.0 (t) - no patch available
High pkg:npm/webpack@5.75.0@5.75.0 (t) upgrade to: 5.76.0
Medium pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
High pkg:npm/minimatch@3.0.4@3.0.4 (t) upgrade to: 3.0.5
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
N/A pkg:npm/jake@10.8.5@10.8.5 (t) - no patch available

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@pantheon-upstream

Copy link
Copy Markdown
Author

Superseeded by #429.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant