? Release Blocker NPM Resource Changed PR-4.4-dev Pending

User tests: Successful: Unsuccessful:

avatar SniperSister
SniperSister
28 Oct 2023

Summary of Changes

Updating TinyMCE to 5.10.8 to fix a mXSS vulnerability, see:
GHSA-v65r-p3vv-jjfv

Testing Instructions

Apply patch, run npm install to download the updated Tiny version, test the editor.

Version 5.10.8 - October 19, 2023
Fixed

Specific HTML content caused mXSS when using undo/redo.
Specific HTML content caused mXSS when using the getContent and setContent APIs with the format: 'raw' option, which also affected the resetContent API and the draft restoration feature of the Autosave plugin.
Notification messages containing HTML were not properly XSS sanitized before being displayed.

avatar SniperSister SniperSister - open - 28 Oct 2023
avatar SniperSister SniperSister - change - 28 Oct 2023
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 28 Oct 2023
Category NPM Change
avatar SniperSister SniperSister - change - 28 Oct 2023
Title
Update TinyMCE to 5.10.8
[4] Update TinyMCE to 5.10.8
avatar SniperSister SniperSister - edited - 28 Oct 2023
avatar SniperSister SniperSister - change - 28 Oct 2023
Title
[4] Update TinyMCE to 5.10.8
[4.4] Update TinyMCE to 5.10.8
avatar SniperSister SniperSister - edited - 28 Oct 2023
avatar dgrammatiko dgrammatiko - test_item - 28 Oct 2023 - Tested successfully
avatar dgrammatiko
dgrammatiko - comment - 28 Oct 2023

I have tested this item ✅ successfully on 285febb


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42239.

avatar heelc29
heelc29 - comment - 28 Oct 2023

Plugin manifest version should be updated too.

avatar SniperSister SniperSister - change - 28 Oct 2023
Labels Added: Release Blocker NPM Resource Changed PR-4.4-dev
avatar joomla-cms-bot joomla-cms-bot - change - 28 Oct 2023
Category NPM Change NPM Change Front End Plugins
avatar SniperSister
SniperSister - comment - 28 Oct 2023

Good catch @heelc29 , done!

avatar SniperSister SniperSister - change - 28 Oct 2023
The description was changed
avatar SniperSister SniperSister - edited - 28 Oct 2023
avatar Fedik Fedik - test_item - 31 Oct 2023 - Tested successfully
avatar Fedik
Fedik - comment - 31 Oct 2023

I have tested this item ✅ successfully on a8980bb


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42239.

avatar Fedik Fedik - change - 31 Oct 2023
Status Pending Ready to Commit
avatar Fedik
Fedik - comment - 31 Oct 2023

r2c


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42239.

avatar Quy Quy - change - 31 Oct 2023
Labels Added: ?
avatar laoneo
laoneo - comment - 2 Nov 2023

Merging as there is currently an issue with mysql 5.7 on appveyor.

avatar laoneo laoneo - close - 2 Nov 2023
avatar laoneo laoneo - merge - 2 Nov 2023
avatar laoneo laoneo - change - 2 Nov 2023
Status Ready to Commit Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2023-11-02 10:03:05
Closed_By laoneo
Labels Added: ?
Removed: ?
avatar laoneo
laoneo - comment - 2 Nov 2023

Thanks!

Add a Comment

Login with GitHub to post a comment