A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display. Reference: https://www.drupal.org/node/1056470
Created drupal6 tracking bugs for this issue: Affects: epel-6 [bug 1795699]
This CVE is for 6.20. EPEL6 has already been at 6.38 for about 4 years (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-00c45982f6) and in addition several security backports for about a year (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-67b3f85ea0). Dependent bug is closed. Please close this bug as well.
Can this bug be closed?
@shawn, bug closed.