Following from #3561325: Create CVEs for December 2025

We should create CVEs for recent advisories.

Maintainers and reporters of modules, we welcome your thoughts and advice about the CWE and CAPEC to assign to these issues.

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

poker10 created an issue. See original summary.

greggles made their first commit to this issue’s fork.

greggles’s picture

Status: Active » Needs review

elc’s picture

Agree these look good for CAS Server:
CWE 91 XML Injection (aka Blind XPath Injection)
CAPEC 233 Privilege Escalation

I've not had a chance to look at the others.

penyaskito’s picture

Not very familiar with CWE or CAPEC so there might be better choices, but from the little I know Canvas SA-contrib-2026-006 LGTM 👍🏽

  • greggles committed e0d74912 on 7.x-1.x
    Issue #3567808: Create CVEs for January 2026
    

  • greggles committed ce605a87 on 7.x-1.x
    Issue #3567808: followup, fix missing bracket broke array
    
greggles’s picture

Status: Needs review » Fixed

These are now filed.

Thanks for the help, @elc and @penyaskito!

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

greggles’s picture

And poker10 - thanks for your help as well :)

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.