Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 724498 (SA-CORE-2020-2, SA-CORE-2020-3) - <www-apps/drupal-{7.70, 8.7.14, 8.8.6}: Multiple vulnerabilities
Summary: <www-apps/drupal-{7.70, 8.7.14, 8.8.6}: Multiple vulnerabilities
Alias: SA-CORE-2020-2, SA-CORE-2020-3
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
Whiteboard: ~4 [noglsa]
Depends on:
Reported: 2020-05-21 19:59 UTC by Tupone Alfredo
Modified: 2020-05-22 01:17 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Tupone Alfredo gentoo-dev 2020-05-21 19:59:00 UTC
www-apps/drupal-7.69 has security vulnerabilities
www-apps/drupal-8.7.13 and www-apps/drupal-8.8.5 is affected

Reproducible: Always
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-21 20:32:47 UTC
Thanks for letting us know about this.

* SA-CORE-2020-2

"The jQuery project released version 3.5.0, and as part of that, disclosed two security vulnerabilities that affect all prior versions. As mentioned in the jQuery blog, both are

    [...] security issues in jQuery’s DOM manipulation methods, as in .html(), .append(), and the others. Security advisories for both of these issues have been published on GitHub."


* SA-CORE-2020-3

"Drupal 7 has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL.

The vulnerability is caused by insufficient validation of the destination query parameter in the drupal_goto() function."

Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-21 20:33:32 UTC
@maintainer(s), please bump to 7.70, 8.7.14, and 8.8.6.
Comment 3 Larry the Git Cow gentoo-dev 2020-05-22 00:57:23 UTC
The bug has been referenced in the following commit(s):

commit 3609c25e2e5c6aa5f3647d0b394d5b4b4b76ddb1
Author:     Jorge Manuel B. S. Vicetto (jmbsvicetto) <>
AuthorDate: 2020-05-22 00:57:15 +0000
Commit:     Jorge Manuel B. S. Vicetto (jmbsvicetto) <>
CommitDate: 2020-05-22 00:57:15 +0000

    www-apps/drupal: Security bumps (8.8.6, 8.7.14 and 7.70).
    8.8.6 and 8.7.14 releases include SA-CORE-2020-002.
    7.70 release includes SA-CORE-2020-002 and SA-CORE-2020-003.
    Package-Manager: Portage-2.3.99, Repoman-2.3.22
    Signed-off-by: Jorge Manuel B. S. Vicetto (jmbsvicetto) <>

 www-apps/drupal/Manifest             |  3 ++
 www-apps/drupal/drupal-7.70.ebuild   | 58 ++++++++++++++++++++++++++++++
 www-apps/drupal/drupal-8.7.14.ebuild | 68 ++++++++++++++++++++++++++++++++++++
 www-apps/drupal/drupal-8.8.6.ebuild  | 68 ++++++++++++++++++++++++++++++++++++
 4 files changed, 197 insertions(+)
Comment 4 Jorge Manuel B. S. Vicetto (RETIRED) gentoo-dev 2020-05-22 00:58:22 UTC
I had started working on this, but took a bit longer than expected to push to the tree [1].

 [1] -
Comment 5 Larry the Git Cow gentoo-dev 2020-05-22 01:00:06 UTC
The bug has been referenced in the following commit(s):

commit c5f67f0520c54f46cff1452953aab2d711cc680c
Author:     Jorge Manuel B. S. Vicetto (jmbsvicetto) <>
AuthorDate: 2020-05-22 00:59:56 +0000
Commit:     Jorge Manuel B. S. Vicetto (jmbsvicetto) <>
CommitDate: 2020-05-22 00:59:56 +0000

    www-apps/drupal: Drop old and vulnerable releases.
    Package-Manager: Portage-2.3.99, Repoman-2.3.22
    Signed-off-by: Jorge Manuel B. S. Vicetto (jmbsvicetto) <>

 www-apps/drupal/Manifest             |  5 ---
 www-apps/drupal/drupal-7.69.ebuild   | 58 ------------------------------
 www-apps/drupal/drupal-8.7.12.ebuild | 68 ------------------------------------
 www-apps/drupal/drupal-8.7.13.ebuild | 68 ------------------------------------
 www-apps/drupal/drupal-8.8.4.ebuild  | 68 ------------------------------------
 www-apps/drupal/drupal-8.8.5.ebuild  | 68 ------------------------------------
 6 files changed, 335 deletions(-)
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-22 01:17:45 UTC
Closing because tree clean, no stable ebuilds. Thank you! :)