Skip to content
This repository was archived by the owner on Aug 8, 2024. It is now read-only.

Update to Drupal 9.5.10. For more information, see https://www.drupal.org/project/drupal/releases/9.5.10 - #432

Closed
pantheon-upstream wants to merge 1 commit into
default-9.xfrom
update-9.5.10
Closed

Update to Drupal 9.5.10. For more information, see https://www.drupal.org/project/drupal/releases/9.5.10#432
pantheon-upstream wants to merge 1 commit into
default-9.xfrom
update-9.5.10

Conversation

@pantheon-upstream

Copy link
Copy Markdown

Update from Drupal 9.1.0 to Drupal 9.5.10.

This is experimental. Do not merge.

@guardrails

guardrails Bot commented Jul 5, 2023

Copy link
Copy Markdown

⚠️ We detected 11 security issues in this pull request:

Hard-Coded Secrets (1)
Severity Details Docs
Medium Title: Secret Keyword
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/user/config/install/user.mail.yml#L34
📚

More info on how to fix Hard-Coded Secrets in General.


Information Disclosure (1)
Severity Details Docs
Medium Title: Use of phpinfo()
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/system/src/Controller/SystemInfoController.php#L62
📚

More info on how to fix Information Disclosure in PHP.


Insecure Access Control (1)
Severity Details Docs
Low Title: Insecure HTTP redirect
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/.ht.router.php#L29
📚

More info on how to fix Insecure Access Control in PHP.


Insecure Processing of Data (2)
Severity Details Docs
Medium Title: Unescaped user input in HTML
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/ckeditor5/js/ckeditor5.es6.js#L652
📚
Medium Title: Unescaped user input in HTML
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/ckeditor5/js/ckeditor5.js#L291
📚

More info on how to fix Insecure Processing of Data in JavaScript.


Insecure Use of Dangerous Function (6)
Severity Details Docs
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/ckeditor5/js/ckeditor5.admin.es6.js#L328
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/ckeditor5/js/ckeditor5.admin.es6.js#L737
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/ckeditor5/js/ckeditor5.admin.js#L184
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/modules/ckeditor5/js/ckeditor5.admin.js#L386
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/themes/olivero/js/second-level-navigation.es6.js#L81
📚
Medium Title: Dynamic evaluation of untrusted input (Frontend)
https://github.com/pantheon-systems/drops-8/blob/8da4b9f5a8b97c6ff62f45ee06faa526f3d9221c/core/themes/olivero/js/second-level-navigation.js#L38
📚

More info on how to fix Insecure Use of Dangerous Function in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@pantheon-upstream

Copy link
Copy Markdown
Author

Superseeded by #433.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant