govCMS / GovCMS8

Current stable release of the main GovCMS8 distribution.
GNU General Public License v2.0
60 stars 58 forks source link

Release/8.x 1.14 #602

Closed suhyeonh closed 3 years ago

suhyeonh commented 3 years ago

Drupal Core update

The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal. For more information please see:CVE-2020-36193

Exploits may be possible if Drupal is configured to allow .tar, .tar.gz, .bz2, or .tlz file uploads and processes them. See: https://www.drupal.org/sa-core-2021-001

Modules update

Comments

It addresses a recent critical security advisory issued by Drupal.org. GovCMS assessed this risk as it applied to D8 distribution. Subsequently the security risk was downgraded to moderately critical.

Deployment is scheduled from 24 February 2021. No outages are expected to websites during the deployment process.

The GovCMS D8 distribution will continue to be supported after this update.

More information

If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/