Displaying 1 - 50 of 78
Title Status Priority Category Version Component Replies Last updatedsort ascending Assigned to Created
Post about welcoming 4 new team members Fixed Normal Task 7.x-1.x-dev Code 3 1 day 18 hours 1 day 18 hours
Script some common needs Needs review Normal Feature request 7.x-1.x-dev Code 5 2 days 17 hours 1 week 4 days
DST policy proposals to deal with the 2026 barrage Active Normal Plan 7.x-1.x-dev Security Working Group (policy questions) 2 3 days 9 hours 3 days 9 hours
Proposed updated requirements for SA release Active Normal Task 7.x-1.x-dev Security Working Group (policy questions) 1 3 days 9 hours 3 days 9 hours
Proposed change advisory release window to Tuesday Active Normal Plan 7.x-1.x-dev Miscellaneous 4 3 days 14 hours 1 week 1 day
September 2026 CVEs Needs review Normal Task 7.x-1.x-dev Code 5 4 days 11 hours 1 month 1 week
Clearly define policy regarding exploits that require 3rd party code Active Normal Task 7.x-1.x-dev Security Working Group (policy questions) 3 4 days 15 hours 5 days 12 hours
Clarify/document our policy about XSS payloads Needs review Normal Task 7.x-1.x-dev Security Working Group (policy questions) 9 5 days 12 hours 3 months 3 days
Request for CVE for File Force fix Needs review Normal Support request 7.x-1.x-dev Code 3 1 week 20 hours 1 week 1 day
Create script to pull advisory data to csv files Fixed Normal Task 7.x-1.x-dev Code 7 1 week 3 days 2 months 3 weeks
Do not create security forks with module name included. Active Major Task 7.x-1.x-dev Miscellaneous 3 1 week 4 days 2 weeks 8 hours
Update policy to explicitly state security issues will be handled privately Active Normal Feature request 7.x-1.x-dev Security Working Group (policy questions) 7 2 weeks 6 days 4 years 1 month
Run a static application security test (SAST) as part of core CI Active Normal Task 7.x-1.x-dev Code 2 3 weeks 2 days 1 year 6 months
Clarify scope for Open Redirect Active Normal Task 7.x-1.x-dev Documentation 4 3 weeks 6 days 1 month 1 week
Publish CVE-2026-19030 for CAPTCHA failure provides login credential validation feedback Needs review Normal Task 7.x-1.x-dev Code 11 1 month 1 day 4 months 1 day
Publish CVE-2026-16136 for Views Reference Filter (enttityreference_filter) Needs review Normal Task 7.x-1.x-dev Code 4 1 month 1 day 3 months 1 week
CVE-2026-77152 - Publish Field Collection CVE ID Needs review Normal Support request 7.x-1.x-dev Code 8 1 month 1 day 2 months 3 weeks
Proposed documentation page: Credentials optionally stored in plain text is not considered a vulnerability Active Normal Task 7.x-1.x-dev Code 5 1 month 6 days 1 month 1 week
Automatically update security release node's short description with SA Active Normal Feature request 7.x-1.x-dev Code 1 1 month 1 week 1 month 1 week
Define standard description for marking an existing permission as "restrict access" Active Normal Task 7.x-1.x-dev Documentation 10 1 month 1 week 5 months 4 weeks
[policy] Treat CAPTCHA bypasses as non-security bugs Active Normal Plan 7.x-1.x-dev Code 21 2 months 6 days 5 months 4 weeks
Policy: AI tools allow "anyone" to attack sites, so lower-score vulnerabilities should still be given SAs Active Normal Feature request 7.x-1.x-dev Security Working Group (policy questions) 4 2 months 6 days 2 months 1 week
CVE request for LDAP - CVE-2026-6908 Needs review Normal Task 7.x-1.x-dev Code 10 2 months 6 days 5 months 4 weeks
Policy about issuing security advisories Active Normal Support request 7.x-1.x-dev Security Working Group (policy questions) 2 2 months 1 week 2 months 1 week
Change policy regarding timeline for resolution and disclosure of security vulnerabilities to be more strict Active Normal Task 7.x-1.x-dev Security Working Group (policy questions) 21 2 months 2 weeks 4 years 4 months
Publish CVE-2026-16132 for Icon Needs review Normal Support request 7.x-1.x-dev Documentation 3 2 months 3 weeks 3 months 1 week
Expand the ability of module maintainers to mark a particular release as security. Active Major Task 7.x-1.x-dev Code 6 3 months 2 weeks 2 years 3 months
Document the labels on security issues in Drupalcode Needs review Normal Task 7.x-1.x-dev Code 8 3 months 2 weeks 3 months 3 weeks
Unsuported Modules: Establish timeline for publishing of vulnerability info to allow for possible CVE creation Active Normal Task 7.x-1.x-dev Documentation 7 4 months 2 days 1 year 9 months
Switch to CVSS scoring Active Normal Task 7.x-1.x-dev Code 17 4 months 2 days 2 years 5 months
OpenID Connect: Request update to CVE-2026-3530 Needs review Normal Task 7.x-1.x-dev Code 3 4 months 1 week 4 months 2 weeks
OpenID Connect: Request update to CVE-2026-3531 Needs review Normal Task 7.x-1.x-dev Code 3 4 months 1 week 4 months 2 weeks
OpenID Connect: Request update to CVE-2026-3532 Needs review Normal Task 7.x-1.x-dev Code 3 4 months 1 week 4 months 2 weeks
CAPTCHA: Request update to CVE-2026-3214 Needs review Normal Task 7.x-1.x-dev Code 2 4 months 1 week 4 months 2 weeks
GitLab security issue template should ask for impacted version Active Normal Bug report 7.x-1.x-dev User interface 1 4 months 2 weeks 4 months 2 weeks
Plan for how to meet 72 hour publication obligation (CNAv4.1 section 4.5.1.4) Active Normal Plan 7.x-1.x-dev Security Working Group (policy questions) 3 4 months 3 weeks 4 months 4 weeks
Documenting the Security/CVE process for D7ES providers Active Normal Task 7.x-1.x-dev Documentation 5 5 months 1 week aangel 1 year 1 month
Review and adopt CWE assignments from NIST Active Normal Task 7.x-1.x-dev Code 1 7 months 4 weeks 7 months 4 weeks
Align DST vulnerability determination criteria to CVE standards Active Critical Support request 7.x-1.x-dev Security Working Group (policy questions) 11 1 year 1 month 2 years 1 month
Incorrect affected versions on advisories Active Normal Bug report 7.x-1.x-dev Miscellaneous 2 1 year 2 months 1 year 2 months
Create CVEs for 2016 (especially for highly critical issues) Active Normal Task 7.x-1.x-dev Code 1 1 year 2 months 1 year 2 months
More flexible language for git vetted status for co-maintainers of existing projects Active Normal Plan 7.x-1.x-dev Code 42 1 year 3 months 3 years 8 months
Allow filtering the All Issues view by version Needs review Normal Feature request 7.x-1.x-dev User interface 3 1 year 3 months 1 year 3 months
Get an Open Source Security Foundation badge for Drupal (core? contrib?) Needs review Normal Task 7.x-1.x-dev Miscellaneous 11 1 year 3 months 4 years 8 months
Clarify the Drupal Security Team Disclosure Policy Active Normal Task 7.x-1.x-dev Code 2 1 year 4 months 1 year 4 months
Policy: Post CVE number / link on private issue Active Normal Feature request 7.x-1.x-dev Documentation 3 1 year 4 months 1 year 4 months
Create a survey for the community prior to Drupalcon Needs work Normal Task 7.x-1.x-dev Code 11 1 year 6 months 1 year 6 months
issues_by_followup_date view should default to Open status Active Normal Bug report 7.x-1.x-dev Code 3 1 year 7 months 1 year 7 months
Prohibit the ability to adopt a project Active Normal Feature request 7.x-1.x-dev Code 16 1 year 8 months 2 years 4 months
Require in-person identity confirmation to receive "Git vetted user" role. Active Normal Feature request 7.x-1.x-dev Code 8 1 year 8 months 2 years 4 months

Pages

Subscribe with RSS Subscribe to Issues for Drupal Security Team