Closed (duplicate)
Project:
Drupal core
Version:
8.0.x-dev
Component:
base system
Priority:
Critical
Category:
Task
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
27 May 2015 at 00:59 UTC
Updated:
27 May 2015 at 07:15 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
joshtaylor commentedComment #2
joshtaylor commentedComment #4
joshtaylor commentedMore info http://symfony.com/blog/cve-2015-4050-esi-unauthorized-access
Comment #5
berdirWe already have a critical to update to 2.7.0 as soon as it's out, which will also include this: #2470693: Upgrade to Symfony 2.7.0
We're not using ESI so I don't think this affects us, so it doesn't seem urgent.
Closing as duplicate, feel free to re-open if you disagree.
Comment #6
joshtaylor commentedWasn't sure if Drupal used ESI or not (which is why I submitted the patch), but if it doesn't then it can wait until 2.7.0 (yay), yes.