Hi,

Some time ago I reported a PostgreSQL injection vulnerability in Drupal. It appeared to have been repaired for a while, but since 11.3.13 it seems to have been somehow 're-introduced', because Patchman, used by my hosting provider reports to have repaired that vulnerability again with the latest updates.

Dirk Engelage

To the house of a friend the road is never long ...

Comments

dirke’s picture

Did anyone take notice of this re-introduction of a previous code injection vulnerability? Or is everyone too busy with the further development of Drupal 11.4.x?

Dirk

ressa’s picture

You probably need to create a Drupal core issue @dirke, the core maintainers are not so active in the Forum: https://www.drupal.org/project/issues/drupal.

dirke’s picture

Hi ressa,

Thanks for your reply and pointer. But when I look into this, it appears to be pretty complicated to find the correct way to create a report. Since I'm not a code developer, but an somewhat experienced user, it's like finding a path in a dense forest. So I will leave it at this. Maybe you have some connection to make them aware of this apparent re-introduction of a failure? Just asking ...

Dirk

dirke’s picture

According to Patchman, running at my hosting service, the PostgreSQL vulnerability is still presrent in the latest 11.4.4 version of Drupal (and most previous versions). Seems like a bad thing, that this still hasn't been solved!!!

Dirk Engelage