
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN291
_____________________________________________________________________

DATE                : 28/05/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Drupal core versions prior to
                             9.1.9, 9.0.14, 8.9.16.

=====================================================================
https://www.drupal.org/sa-core-2021-003
_____________________________________________________________________

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-003


Project:          Drupal core
Date:             2021-May-26
Security risk:
Moderately critical 14∕25 AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Default
Vulnerability:    Cross Site Scripting


Description:

Drupal core uses the third-party CKEditor library. This library has an
error in parsing HTML that could lead to an XSS attack. CKEditor 4.16.1
and later include the fix.

Users of the CKEditor library via means other than Drupal core should
update their 3rd party code (e.g. the WYSIWYG module for Drupal 7). The
Drupal Security Team policy is not to alert for issues affecting 3rd
party libraries unless those are shipped with Drupal core. See
DRUPAL-SA-PSA-2016-004 for more details.

This issue is mitigated by the fact that it only affects sites with
CKEditor enabled.


Solution:

Install the latest version:

    If you are using Drupal 9.1, update to Drupal 9.1.9.
    If you are using Drupal 9.0, update to Drupal 9.0.14.
    If you are using Drupal 8.9, update to Drupal 8.9.16.

Versions of Drupal 8 prior to 8.9.x are end-of-life and do not receive
security coverage.


Reported By:

    Or Sahar

Fixed By:

    Greg Knaddison of the Drupal Security Team
    Jess of the Drupal Security Team
    Krzysztof Krzton
    Lee Rowlands of the Drupal Security Team
    Michael Hess of the Drupal Security Team




=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================



