core – Critical – Arbitrary PHP code execution – SA-CORE-2021-002

Project Drupal 10 Maintenance and Support Service  core Date Drupal 10 Maintenance and Support Service  2021-January-16 Security risk Drupal 10 Maintenance and Support Service  Critical 16∕25 AC Drupal 10 Maintenance and Support ServiceComplex/A Drupal 10 Maintenance and Support ServiceAdmin/CI Drupal 10 Maintenance and Support ServiceAll/II Drupal 10 Maintenance and Support ServiceAll/E Drupal 10 Maintenance and Support ServiceTheoretical/TD Drupal 10 Maintenance and Support ServiceAll Vulnerability Drupal 10 Maintenance and Support Service  Arbitrary PHP code execution Description Drupal 10 Maintenance and Support Service  A remote code execution vulnerability exists in PHP’s built-in phar stream wrapper when performing file operations on an untrusted phar Drupal 10 Maintenance and Support Service// URI. Some code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration. Solution Drupal 10 Maintenance and Support Service  If you are using 8.6.x, upgrade to 8.6.6. If you are using 8.5.x or earlier, upgrade to 8.5.9. If you are using 7.x, upgrade to 7.62. Versions of 8 prior to 8.5.x are end-of-life and do not receive security coverage. Known issues This fix introduced a fatal error for some Drush installatiosn when updating a site with Drush. New releases (8.6.7, 8.5.10, and 7.63) have been issued to resolve this regression. See the release notes for additional details. Update information .phar added to dangerous extensions list The .phar file extension has been added to ’s dangerous extensions list, which means that any such file uploaded to a file field will automatically be converted to a text file (with the .txt extension) to prevent it from being executed. This is similar to how handles file uploads with a .php extension. phar Drupal 10 Maintenance and Support Service// stream wrapper disabled by default for 7 sites on PHP 5.3.2 and earlier The replacement stream wrapper is not compatible with PHP versions lower than 5.3.3. 8 requires a higher PHP version than that, but for 7 sites using lower PHP versions, the built-in phar stream wrapper has been disabled rather than replaced. 7 sites using PHP 5.2 (or PHP 5.3.0-5.3.2) that require phar support will need to re-enable the stream wrapper for it; however, note that re-enabling the stream wrapper will re-enable the insecure PHP behavior on those PHP versions. It is very uncommon to both be running a PHP version lower than 5.3.3 and to need phar support. If you’re in that situation, consider upgrading your PHP version instead of restoring insecure phar support. Reported By Drupal 10 Maintenance and Support Service  Greg Knaddison of the Security Team Fixed By Drupal 10 Maintenance and Support Service  Cash Williams of the Security Team Lee Rowlands of the Security Team Samuel Mortenson of the Security Team Jess of the Security Team Alex Pott of the Security Team Ted Bowman Michael Hess of the Security Team Alex Bronstein of the Security Team Fabian Franz Additional information Note Drupal 10 Maintenance and Support Service Going forward, core will issue individual security advisories for separate vulnerabilities included in the release, rather than lumping “multiple vulnerabilities” into a single advisory. All advisories released today Drupal 10 Maintenance and Support Service SA-CORE-2021-001 SA-CORE-2021-002 Updating to the latest core release will apply the fixes for all the above advisories. Source Drupal 10 Maintenance and Support Service https Drupal 10 Maintenance and Support Service//www.Drupal 10.org/security/rss.xml Source Drupal 10 Maintenance and Support Service Drupal 10 blender

This article was republished from its original source.
Call Us: 1(800)730-2416

Pixeldust is a 20-year-old web development agency specializing in Drupal and WordPress and working with clients all over the country. With our best in class capabilities, we work with small businesses and fortune 500 companies alike. Give us a call at 1(800)730-2416 and let’s talk about your project.

FREE Drupal SEO Audit

Test your site below to see which issues need to be fixed. We will fix them and optimize your Drupal site 100% for Google and Bing. (Allow 30-60 seconds to gather data.)

Powered by

core – Critical – Arbitrary PHP code execution – SA-CORE-2021-002

On-Site Drupal SEO Master Setup

We make sure your site is 100% optimized (and stays that way) for the best SEO results.

With Pixeldust On-site (or On-page) SEO we make changes to your site’s structure and performance to make it easier for search engines to see and understand your site’s content. Search engines use algorithms to rank sites by degrees of relevance. Our on-site optimization ensures your site is configured to provide information in a way that meets Google and Bing standards for optimal indexing.

This service includes:

  • Pathauto install and configuration for SEO-friendly URLs.
  • Meta Tags install and configuration with dynamic tokens for meta titles and descriptions for all content types.
  • Install and fix all issues on the SEO checklist module.
  • Install and configure XML sitemap module and submit sitemaps.
  • Install and configure Google Analytics Module.
  • Install and configure Yoast.
  • Install and configure the Advanced Aggregation module to improve performance by minifying and merging CSS and JS.
  • Install and configure Schema.org Metatag.
  • Configure robots.txt.
  • Google Search Console setup snd configuration.
  • Find & Fix H1 tags.
  • Find and fix duplicate/missing meta descriptions.
  • Find and fix duplicate title tags.
  • Improve title, meta tags, and site descriptions.
  • Optimize images for better search engine optimization. Automate where possible.
  • Find and fix the missing alt and title tag for all images. Automate where possible.
  • The project takes 1 week to complete.