Closed (fixed)
Project:
Drupal.org customizations
Component:
Miscellaneous
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
10 Jan 2008 at 22:00 UTC
Updated:
21 Aug 2014 at 21:00 UTC
Jump to comment: Most recent
Comments
Comment #1
gerhard killesreiter commentedThere's a problem with the codefilter module.
Comment #2
gerhard killesreiter commentedI had to disable the codefilter module becaue it doesn't work with the new utf8 validation that was introduced by the security release.
Comment #3
dwwSubmitted a critical bug against code filter for this: http://drupal.org/node/208636
@killes if you have any more info you could add to that issue about what you discovered while debugging (if anything), it might help the code filter maintainers get a patch working sooner.
thanks,
-derek
Comment #4
zeta ζ commentedDoes being able to see a part of the page with Revisions – show diff, constitute a vulnerability? or is this only possible because that part I could see doesn’t contain any offending code. Would codefilter catch it, if it did?
Comment #5
heine commentedCodefilter has been disabled because of the issue Drupal 5.6 breaks Code Filter due to Fix for SA-20.
There's no risk in having the content displayed on the revisions.
Comment #6
zeta ζ commentedfixed by http://drupal.org/node/208636
Comment #7
Anonymous (not verified) commentedAutomatically closed -- issue fixed for two weeks with no activity.