Closed (fixed)
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Support request
Assigned:
Unassigned
Reporter:
Created:
9 Feb 2026 at 20:46 UTC
Updated:
16 Apr 2026 at 22:40 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
gregglesThanks! I think the project should stay as core, but we can update the description to link to the D7 project page.
Seems fine to leave CVSS out.
Comment #3
aangel commented"I think the project should stay as core, but we can update the description to link to the D7 project page."
Might not be necessary. What I did was actually add a second product (which I didn't know you could do until I clicked the button). Product 1 is modern Drupal, product 2 is D7.
1. The first product continues to use core and all details are for modern Drupal.
2. The second product uses for https://www.drupal.org/project/link and https://git.drupalcode.org/project/link and version #'s are for D7.
3. The description is in common so I added the version #'s for D7 but that's it.
With this setup, I think it's clear to the reader where to find links for each distinct product...all because they allow multiple products.
Comment #4
gregglesThat seems good. I tried to diff this against the current CVE but it seems quite different so I'm hesitant to just post this. Can you take a look at that? Maybe post a diff with your original cve?
Comment #5
aangel commentedSorry about that. There were a few extraneous changes (metadata, stripped date stamp and the orgId—not sure how that bit happened) that I restored in this new version. This should apply cleanly. Here is a diff:
Comment #6
gregglesNow published!
Thanks.