I've godt a message from my host:
Our automated vulnerability scanner has detected outdated software with known security vulnerabilities in the Pro Suite installation for cbmsupport.dk.
The vulnerabilities have been automatically patched, so the issue has already been mitigated.
It is still recommended to update any CMS components, themes, and plugins on the installation to their latest versions to ensure a permanent fix.
The affected file is:
/var/www/cbmsupport.dk/kb10/web/core/lib/Drupal/Core/Entity/Query/Sql/pgsql/Condition.php
Drupal core — Highly critical — SQL injection — SA‑CORE‑2026‑004"
Comments
Comment #2
cilefen commentedComment #3
daffie commentedWhen the big get fixed by patching, the software version does not get updated. The check on software with vulnerabilities is by version, no the actual code. Run "composer update" to fix the warning message.
Comment #5
mcdruid commentedUnpublishing this issue for now; will discuss further in a private security issue (where we'll add participants from this public issue).
Comment #6
mcdruid commentedre-publishing; the issue outlined in my previous comment is being handled in a public followup: https://www.drupal.org/project/drupal/issues/3614837