govCMS / GovCMS8

Current stable release of the main GovCMS8 distribution.
GNU General Public License v2.0
61 stars 58 forks source link

[GOVCMSD8-806] Update core to 8.9.13 #601

Closed suhyeonh closed 3 years ago

suhyeonh commented 3 years ago

Security Advisory - https://www.drupal.org/sa-core-2021-001 Project: Drupal core [1] Date: 2021-January-20 Security risk: Critical 18∕25 AC:Complex/A:User/CI:All/II:All/E:Exploit/TD:Uncommon [2] Vulnerability: Third-party libraries

Description:  The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal.  For more information please see:

   * CVE-2020-36193 [3]

Exploits may be possible if Drupal is configured to allow .tar, .tar.gz, .bz2, or .tlz file uploads and processes them.

Solution:  Install the latest version:

Versions of Drupal 8 prior to 8.9.x are end-of-life and do not receive security coverage.