Drupal core
A person with an ordinary account who can create or edit content could hide harmful code on the site. If a site administrator or another user with access to the visual text editor views that content, the code could run and let the attacker view private information or change content. The attacker could not do this without someone else viewing the content first.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the site is set up to use the CKEditor visual text editor.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Drupal core to 11.4.7, 11.3.17 or 10.6.17, whichever branch you are on.
For developers: what the fix changed
The provided diff consists of minified CKEditor 5 build files, making it impossible to confidently isolate the specific changes that fix the XSS vulnerability in the engine package.
The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.
Also in this release The release updates the CKEditor 5 library to a new version, resulting in widespread minification and module ID changes across the compiled assets.
composer.lock+5 −5composer/Metapackage/CoreRecommended/composer.json+2 −2composer/Metapackage/DevDependencies/composer.json+1 −1composer/Metapackage/PinnedDevDependencies/composer.json+2 −2core/assets/vendor/ckeditor5/autosave/autosave.js+1 −1 fixcore/assets/vendor/ckeditor5/basic-styles/basic-styles.js+0 −0core/assets/vendor/ckeditor5/block-quote/block-quote.js+1 −1 fixcore/assets/vendor/ckeditor5/bookmark/bookmark.js+0 −0core/assets/vendor/ckeditor5/ckbox/ckbox.js+0 −0core/assets/vendor/ckeditor5/ckeditor5-dll/ckeditor5-dll.js+0 −0core/assets/vendor/ckeditor5/code-block/code-block.js+0 −0core/assets/vendor/ckeditor5/editor-balloon/editor-balloon.js+1 −1 fix