Problem/Motivation
The module has a potential Remote code injection vulnerability due to depending on 0.8.4 of the dompdf/dompdf package: https://git.drupalcode.org/project/entity_print/-/blob/85f8e5fe/composer...
References:
- https://github.com/advisories/GHSA-x752-qjv4-c4hc
- https://github.com/Roave/SecurityAdvisories/commit/8de287d3e2b7504c77a6f...
Originally reported by codebymikey to the security queue, but can be public under https://www.drupal.org/psa-2011-002
Steps to reproduce
Proposed resolution
Update the minimum constraint
Remaining tasks
User interface changes
API changes
Data model changes
| Comment | File | Size | Author |
|---|---|---|---|
| #5 | 3274668.patch | 281 bytes | larowlan |
Comments
Comment #4
larowlanComment #5
larowlanComment #7
larowlanCutting 8.x-2.5