Skip to content
This repository was archived by the owner on Aug 8, 2024. It is now read-only.

Update to Drupal 9.5.8. For more information, see https://www.drupal.org/project/drupal/releases/9.5.8 - #429

Closed
pantheon-upstream wants to merge 1 commit into
default-9.xfrom
update-9.5.8
Closed

Update to Drupal 9.5.8. For more information, see https://www.drupal.org/project/drupal/releases/9.5.8#429
pantheon-upstream wants to merge 1 commit into
default-9.xfrom
update-9.5.8

Conversation

@pantheon-upstream

Copy link
Copy Markdown

Update from Drupal 9.1.0 to Drupal 9.5.8.

This is experimental. Do not merge.

@guardrails

guardrails Bot commented Apr 19, 2023

Copy link
Copy Markdown

⚠️ We detected 22 security issues in this pull request:

Hard-Coded Secrets (1)
Severity Details Docs
Medium Title: Secret Keyword
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/user/config/install/user.mail.yml#L34
📚

More info on how to fix Hard-Coded Secrets in General.


Insecure Use of Regular Expressions (4)
Severity Details Docs
Medium Title: Regex DOS (ReDOS)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/misc/position.es6.js#L30
📚
Medium Title: Regex DOS (ReDOS)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/misc/position.js#L13
📚
Medium Title: Regex DOS (ReDOS)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/scripts/js/ckeditor5-types-documentation.js#L30
📚
Medium Title: Regex DOS (ReDOS)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/scripts/js/vendor-update.js#L34
📚

More info on how to fix Insecure Use of Regular Expressions in JavaScript.


Information Disclosure (1)
Severity Details Docs
Medium Title: Use of phpinfo()
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/system/src/Controller/SystemInfoController.php#L62
📚

More info on how to fix Information Disclosure in PHP.


Vulnerable Libraries (7)
Severity Details
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
Medium pkg:npm/jquery-form@4.3.0@4.3.0 (t) - no patch available
High pkg:npm/minimatch@3.0.4@3.0.4 (t) upgrade to: 3.0.5
Critical pkg:npm/vm2@3.9.12@3.9.12 (t) upgrade to: 3.9.15
N/A pkg:npm/jake@10.8.5@10.8.5 (t) - no patch available
Medium pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
High pkg:npm/webpack@5.75.0@5.75.0 (t) upgrade to: 5.76.0

More info on how to fix Vulnerable Libraries in JavaScript.


Insecure Use of Dangerous Function (6)
Severity Details Docs
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/ckeditor5/js/ckeditor5.admin.es6.js#L328
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/ckeditor5/js/ckeditor5.admin.es6.js#L737
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/ckeditor5/js/ckeditor5.admin.js#L184
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/ckeditor5/js/ckeditor5.admin.js#L386
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/themes/olivero/js/second-level-navigation.es6.js#L81
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/themes/olivero/js/second-level-navigation.js#L38
📚

More info on how to fix Insecure Use of Dangerous Function in JavaScript.


Insecure Processing of Data (3)
Severity Details Docs
Low Title: Insecure HTTP redirect
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/.ht.router.php#L29
📚
Medium Title: Unescaped user input in HTML
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/ckeditor5/js/ckeditor5.es6.js#L652
📚
Medium Title: Unescaped user input in HTML
https://github.com/pantheon-systems/drops-8/blob/c36d836fed694523bcb53966409e5663210cd7b0/core/modules/ckeditor5/js/ckeditor5.js#L291
📚

More info on how to fix Insecure Processing of Data in PHP and JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@pantheon-upstream

Copy link
Copy Markdown
Author

Superseeded by #431.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant