Hello,

Could we get a 2.x and 1.x CK release to incorporate the security update for SA-CORE-2021-004?

Many thanks!

Comments

mlecha created an issue. See original summary.

Jon Pollard’s picture

yes, agreed, that would be great!

twelvell’s picture

When could the update for SA-CORE-2021-004 be ready?

Jon Pollard’s picture

Just to clarify, I'm agreeing that it would be a great idea - not that I can do it...

twelvell’s picture

Is commerce kickstart abandoned?

rar’s picture

I updated with "drush up" and had no adverse issues. No database updates were required.

I don't know why there is the statement that one should only update using commerce kickstart profile instead of individual modules or just updating core.

Jon Pollard’s picture

I tweeted Ryan Szarama re the lack of a new release and he replied:

Yeah, we’ll get ‘em in ASAP. In the meantime, the mitigation is to not permit untrusted users to use CKEditor if I read the SA right.

rszrama’s picture

Version: 7.x-2.71 » 7.x-2.x-dev

Updating core to Drupal 7.82 as with the 1.x branch.

  • rszrama committed cbf4697 on 7.x-2.x
    Issue #3225091 by rszrama: Update Drupal core to 7.82
    
rszrama’s picture

Status: Active » Fixed

Committed. Tagging the release.

Jon Pollard’s picture

Not sure if I'm missing something, but the releases for 2.x versions are both still dated May 11th

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

mlecha’s picture

Hello,

Probably an oversight, but no release appeared on drupal.org. Could we get releases built for this security notice?

Huge thank you!

rar’s picture

@mlecha It looks like the release that contains Drupal 7.82 is

commerce-kickstart-7.x-1.68 Stable release covered by the Drupal Security Team released 3 September 2021

which appears below 7.x-2.71 on the project page.

Details at https://www.drupal.org/project/commerce_kickstart/releases/7.x-1.68

Yes, I see that .68 is a lower number than .71, but when I look in the tar file for the .68 release, I see the .82 drupal-core updates in the CHANGELOG.txt file.

Edit: I'm wrong. Confused KIckstart 1 vs Kickstart 2

Jon Pollard’s picture

There are 2 separate versions of kickstart, version 1 and version 2... 7.x-1.68 is version 1

Ollie222’s picture

Echoing the above comments, thanks for patching this and a new release would be great.