[ASA-202106-35] drupal: cross-site scripting
Arch Linux Security Advisory ASA-202106-35 ========================================== Severity: High Date : 2021-06-15 CVE-ID : CVE-2021-33829 Package : drupal Type : cross-site scripting Remote : Yes Link : Summary ======= The package drupal before version 9.1.10-1 is vulnerable to cross-site scripting. Resolution ========== Upgrade to 9.1.10-1. # pacman -Syu "drupal>=9.1.10-1" The problem has been fixed upstream in version 9.1.10. Workaround ========== None. Description =========== Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to a cross-site scripting (XSS) attack. CKEditor 4.16.1 and later, as bundled with Drupal 9.1.9, include the fix. Impact ====== A remote attacker could execute arbitrary JavaScript code through cross-site scripting using crafted HTML code. References ==========