CKEditor, a third-party JavaScript library included in Drupal core, has fixed a cross-site scripting (XSS) vulnerability. The vulnerability stemmed from the fact that it was possible to execute XSS inside CKEditor when using the image2 plugin (which Drupal 8 core also uses).

Part of security release SA-CORE-2018-003

This vulnerability affects the following application versions:

  • Drupal 8.3.0
  • Drupal 8.3.1
  • Drupal 8.3.2
  • Drupal 8.3.3
  • Drupal 8.3.4
  • Drupal 8.3.5
  • Drupal 8.3.6
  • Drupal 8.3.7
  • Drupal 8.3.8
  • Drupal 8.3.9
  • Drupal 8.4.0
  • Drupal 8.4.1
  • Drupal 8.4.2
  • Drupal 8.4.3
  • Drupal 8.4.4
  • Drupal 8.4.5
  • Drupal 8.4.6
  • Drupal 8.5.0
  • Drupal 8.5.1

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *