Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. Not all sites and users are affected, but configuration changes to prevent the exploit might be impractical and will vary between sites. Therefore, we recommend all sites update to this release as soon as possible. References: https://www.drupal.org/sa-core-2021-002
Created drupal7 tracking bugs for this issue: Affects: epel-7 [bug 1953011] Affects: fedora-all [bug 1953010]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.