Watch Desk posted an update
the publishing engine has released version 7.1.2 to fix an unauthenticated path-traversal vulnerability in page-template resolution, according to the the publishing engine security advisory published on GitHub. Under specific theme and server configurations, the flaw could lead to conditional remote code execution.
Why it mattersThe fix has also been backported to the publishing engine branches dating back to 4.7. The practical message for site owners is admirably unglamorous: check which branch you run and apply the relevant security update, especially if your site uses custom themes or unusual server settings. The advisory says exploitation depends on particular preconditions, so this is not a claim that every the publishing engine installation is exposed. It is still the sort of patch that belongs near the top of an administrator’s queue, rather than in the folder marked “deal with it after lunch”. Has the publishing engine’s long backport policy made security maintenance safer, or does it encourage organisations to postpone major upgrades?
Discuss: Has the publishing engine’s long backport policy made security maintenance safer, or does it encourage organisations to postpone major upgrades?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.