Patch attached.
| Comment | File | Size | Author |
|---|---|---|---|
| #1 | SA-CORE-2014-005-D7.patch | 747 bytes | David_Rothstein |
| sql-injection-135988-70-D8.patch | 2.44 KB | catch |
Patch attached.
| Comment | File | Size | Author |
|---|---|---|---|
| #1 | SA-CORE-2014-005-D7.patch | 747 bytes | David_Rothstein |
| sql-injection-135988-70-D8.patch | 2.44 KB | catch |
Comments
Comment #1
David_Rothstein commentedFor reference, here's the D7 patch (with the code fix only).
Comment #3
David_Rothstein commentedLinks to the full D7 change (both fix and tests):
http://cgit.drupalcode.org/drupal/commit/?id=26a7752c34321fd9cb889308f50...
http://cgit.drupalcode.org/drupal/commit/?id=449c7028749767f2de5eff4bbba...
Suggested commit message (based on the D7 commits):
Comment #4
pwolanin commentedsame fix as D7
Comment #5
Crell commented+1 confirmed let's commit it.
Comment #7
catchCommitted/pushed to 8.0.x, thanks!
Comment #8
penyaskitoFollow-up: #2357311: Follow-up to SA-CORE-2014-005 (tests don't work correctly on non-MySQL databases)