En

Drupal官网安全更新(2023-08-02)

来源:Drupal官网 发布日期:2023-08-02 阅读次数:4828 评论:0

基本信息

发布日期:2023-08-02(官方当地时间)

更新类型:安全更新

更新版本:10.1.2

感知时间:2023-08-02 18:50:04

风险等级:未知

情报贡献:TSRC

更新标题

drupal 10.1.2

更新详情

This is a patch (bugfix) release of Drupal 10 and is ready for use on production sites. Learn more about Drupal 10.

Drupal 10.1.x will receive security coverage until June 2024.
Important update information
If you are updating from Drupal 9, refer to Preparing your site to upgrade to a newer major version for tools you can use to check the Drupal 10 compatibility of modules, themes and sites. Then, upgrade from Drupal 9 to 10. You should also check the Drupal 10.0.0 release notes.
Important changes in this release


cspell, eslint, and stylelint have been updated to later releases to address upstream security vulnerabilities.


All changes in this release

Issue #3378088 by mstrelan, agunjan085: Invalid references to contextual_pre_render_links in contextual.api.php
Issue #3231503 by mdupont, kiseleva.t, donquixote, akalam, larowlan, joachim, longwave, mglaman: hook_entity_extra_field_info() is called unnecessarily often, hurting performance
Issue #3317745 by heykarthikwithu, mkalkbrenner, catch, smustgrave, Schoenef: CSS Aggregation should not rewrite # url
Issue #3376177 by nlisgo, smustgrave, amateescu: Errors on WorkspacePublishForm::submitForm are not being logged
Issue #3366257 by amateescu: The active workspace is not deactivated when it's deleted
Issue #3376293 by nlisgo, smustgrave, amateescu: WorkspacePublishForm $redirectDestination parameter appears not to be used
Issue #3377207 by bnjmnm, smustgrave: Dialog close icon not reliably visible in forced colors mode
Issue #2952488 by smustgrave, pminf, dcgoodwin, andypost, pau1_m, sim_1, boulaffasae, idebr, jmickela, barone, mgifford, jgloverattronedotcom, andrewmacpherson, DuaelFr, larowlan, lauriii, RachelOlivero: Use aria-current=page in pagination links
Issue #3261663 by s.messaris, DieterHolvoet, ShaunDychko, smustgrave, schillerm, dww: Password reset json endpoint reveals whether an email or username is in use
Issue #3339780 by Nikolas Haliotis, quietone: Move getContent and getContentUpdate inline
Issue #3374223 by andypost, smustgrave, neclimdul: Fix deprecated overloaded function usage in PHP 8.3
Issue #2800691 by bharath-kondeti, djsagar, ravi.shankar, Rishabh Vishwakarma, shashikant_chauhan, quietone, smustgrave, FeyP, joachim, Amber Himes Matz: Improve docs for the Xss::filter() $html_tags parameter
Issue #3375276 by DieterHolvoet: 4xx HTTP code theme suggestions are not applied if a node is set as 4xx path
Issue #3365464 by sarahjean, Gauravvvv, e0ipso: Create new SDC component for Umami Branding
Issue #3371358 by catch, tikaszvince, smustgrave, larowlan: When AssetControllerBase delivers existing file should add content-type
Issue #3376263 by Spokje: Tighten xpath selectors to decrease complexity in tests
Issue #2730807 by Lendude, versantus.nik, cilefen, xjm, SidneyGijzen, smustgrave, almaudoh, alexpott, danflanagan8, jordan.jamous: WSOD on admin/modules if description is set but is NULL in module.info.yml
Issue #3219475 by quietone, adeshsharma, ravi.shankar, lucienchalom, Akram Khan, Prem Suthar, Ratan Priya, andregp, murilohp, karishmaamin, longwave, smustgrave, xjm: Fix spelling for words used once, beginning with 'j' -> 'm', inclusive
Issue #3375806 by urvashi_vora, Lendude, tinto, Harish1688, finne: Views 'Rearrange' dialog show the 'Remove' checkbox, which should be visually hidden
Issue #3370179 by fago, Wim Leers, borisson_, smustgrave: Clarify why FieldConfigBase::getDataType() is 'list' and not 'field_config_base'
Issue #3370828 by catch, longwave, sime, Chi, lauriii, larowlan, agarzola: Ensure that edge caches are busted on deployments for css/js aggregates
Issue #3368145 by Spokje: Use constants when calling CommentTestBase::setCommentAnonymous
Issue #3136459 by ranjith_kumar_k_u, dishabhadra, Gauravvvv, priyanka.sahni, smustgrave, sheldonreed3: Filter tips disappear when changing of text format is cancelled
Issue #3360442 by _andrew, matthew.h, aziza_a, Lendude, Kristen Pol: Prevent the Advanced details getting closed when making changes in the advanced section
Issue #3364867 by eiriksm: Wrong type of property MenuLinkContent::$link
Issue #3364204 by Sweetchuck: Locale configuration storage passes wrong arguments to install storage
Issue #3261229 by mfb, danflanagan8, smustgrave, daffie, catch, alexpott: Passing null to parameter #1 ($num) of type int|float to abs() is deprecated
Issue #3374878 by Spokje: Fix PHPStan L1 errors "Offset 'foo' on array{} in isset() does not exist."
Issue #3375600 by gabriel.passarelli, Gauravvvv, carolpettirossi: Form layout when the "main" region has a smaller height than the "secondary" region is broken
Issue #3356372 by Gauravvvv, BEGRAFX, smustgrave: Bad Color combination in "Block Layout" Example page
Issue #3368277 by sidharth_soman, joachim: document that config/optional is safe to use with duplicate configuration
Revert "Issue #3312072 by penyaskito, markconroy, ckrina: Display category-related recipes when seeing a recipe full page"
Issue #3312072 by penyaskito, markconroy, ckrina: Display category-related recipes when seeing a recipe full page
Issue #3374319 by catch, longwave: FileSystem::deleteRecursive() shouldn't log a message when it tries to delete a non-existent directory
Issue #3372789 by aaron.ferris, larowlan: run-tests.sh references a non existent obsolete Core module's (simpletest) url
Issue #3224941 by andypost, Akram Khan, ravi.shankar, SandeepSingh199, Spokje, catch, xjm, alexpott: Remove usage of setAccessible() when core requires PHP 8.1
Issue #3374664 by Spokje: Security update multiple JavaScript dependencies
Issue #3374660 by Niklan, catch, andypost, Chi, Spokje: Update mck89/peast composer dependency to 1.15.2
Issue #3373867 by lauriii, Eric_A, smustgrave: [regression] "Comments field is required" when creating content for types with a comment field configured as hidden
Issue #3333215 by enchufe, arunkumark, mfb, Nitin shrivastava, smustgrave, cilefen: Return early if syslog configs are NULL to avoid openlog deprecation
Issue #3362898 by Gauravvvv, Vidushi Mehta, athyamvidyasagar, kopeboy, smustgrave: Password input width is incoherent and overflows
Issue #3365451 by amanire, Gauravvvv, smustgrave: Create new SDC component for Umami (disclaimer)
Issue #3335670 by Gauravvvv, sonam.chaturvedi, smustgrave: Claro: Text overlaps the icon in select list on rtl
Issue #3372922 by Spokje, darvanen, msbtterswrth, Wim Leers: Regression: infinite height prevention disables scrolling in Source view
Issue #3373328 by catch, keshav.k, Ambient.Impact, longwave: ^10.1 CSS aggregation breaks during maintenance mode
Issue #3362590 by Santosh_Verma, lauriii, Gauravvvv, Harish1688, amietpatial, smustgrave: There is a noticeable white border on the right side of "Place Block" button
Issue #3040258 by amateescu, adityasingh, anushrikumari, larowlan, s_leu, dixon_, catch, atul4drupal, alexpott, Fabianx: Menu link content changes are not visible on non-live workspaces
Issue #3371992 by andypost, daffie: Tests should check sqlite version using PDO_sqlite extension
Revert "Issue #3362083 by mondrake, smustgrave, longwave, Wim Leers: '@requires externalCommand' is not parsed in PHPUnit 10"
Issue #3362083 by mondrake, smustgrave, longwave, Wim Leers: '@requires externalCommand' is not parsed in PHPUnit 10
Revert "Issue #3358384 by Spokje, mondrake: Deprecate \Drupal\Tests\RandomGeneratorTrait::randomStringValidate"
Issue #3358384 by Spokje, mondrake: Deprecate \Drupal\Tests\RandomGeneratorTrait::randomStringValidate
Issue #3373066 by lauriii: Replace BDFL with Project Lead
Issue #3372678 by lauriii, Berdir: Ajax state leaking to Views bulk operations
Issue #2826826 by vasike, dpi, raman.b, rpayanm, jibran, gpap, mpolishchuck, rwohleb, ranjith_kumar_k_u, smustgrave, johnnydarkko, mrinalini9, Zarpele, Berdir, amateescu, hchonov, amitaibu, larowlan, heddn, RoySegall, quietone: Entity autocomplete widget does not pass along entity to AJAX request
Issue #3370222 by Lendude, solideogloria: Grouped filters with a value of zero do not show when editing the filter
Issue #3325571 by Murz, andypost, smustgrave, catch, larowlan: MemoryStorage fails with "Argument #1 ($array) must be of type array" error on calling function readMultiple()
Issue #3355841 by mondrake: Allow DriverSpecificSchemaTestBase::testChangePrimaryKeyToSerial to execute for non-core drivers
Issue #3338973 by Lendude, cbfannin, ericdsd, marc.groth: Deprecated: preg_split(): Passing null in argument_validator
Issue #3370619 by andypost: Capitalize test group for typedData
Issue #3363711 by Chris Matthews, Nishant, Shiv_Sharma, smustgrave: Minor hyperlink edit on Appearance page
Issue #3345149 by lauriii, shoroshanska, ranjith_kumar_k_u, quietone, smustgrave, tim.plunkett, mlncn, drugan, narendraR: Extra Default value field when adding a field with an unlimited values
Issue #3372638 by lauriii, smustgrave: Page scrolls when element inside bulk operations is focused
Issue #3372783 by Spokje: Re-enable \Drupal\Tests\taxonomy\Functional\Rest\VocabularyJsonAnonTest::testGet
Release type: Bug fixes

软件描述

Drupal是使用PHP语言编写的开源内容管理框架(CMF),它由内容管理系统(CMS)和PHP开发框架(Framework)共同构成。

CVE编号

TSRC分析

暂无

业界资讯

暂无

评论

提交评论 您输入的评论有误,请重新输入