Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6. Reference: https://www.drupal.org/sa-core-2020-009
> 8.9.X versions prior to 8.9.6 Version 8.9.11 releases: - f32: https://bodhi.fedoraproject.org/updates/FEDORA-2020-d50d74d6f2 - f33: https://bodhi.fedoraproject.org/updates/FEDORA-2020-6f1079934c - f34+: https://bodhi.fedoraproject.org/updates/FEDORA-2020-03e30ffa1c Please close this bug