[Bug 265883] www/drupal9 is out of date, affected by multiple CVEs

From: <bugzilla-noreply_at_freebsd.org>
Date: Tue, 16 Aug 2022 16:05:17 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=265883

            Bug ID: 265883
           Summary: www/drupal9 is out of date, affected by multiple CVEs
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: acm@FreeBSD.org
          Reporter: f451@imap.cc
          Assignee: acm@FreeBSD.org
             Flags: maintainer-feedback?(acm@FreeBSD.org)

Hi,

drupal 9.3.21 is available. Our ports version is 9.3.19.

https://www.drupal.org/project/drupal/releases/9.3.20 references
https://github.com/advisories/GHSA-8274-h5jp-97vr (CVE-2022-31109)

https://www.drupal.org/project/drupal/releases/9.3.21 references
https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-42wq-rch8-6f6j
(CVE-2022-31175)

Please update. many thanks,

-- 
You are receiving this mail because:
You are the assignee for the bug.