Fedora 21 : drupal7-migrate-2.8-1.fc21 (2015-11314)

high Nessus Plugin ID 84849

Synopsis

The remote Fedora host is missing a security update.

Description

## 7.x-2.8

**See [SA-CONTRIB-2015-130](https://www.drupal.org/node/2516678)**

**Features and enhancements**

- Issue #2379289: migrate-import --update does not seem to work as expected, if map is not joinable, due to highwater field?

- Issue #2403643: Migration::applyMappings() unable to handle multifield subfields

- Issue #2472045: Add language subfields only if field is translatable

- Issue #2474809: Obtuse error message when migration dependencies are missing

- Issue #2397791: MigrationBase::handleException should handle multiple errors via field_attach_validate()

- Issue #2309563: Add support for running migrations via wildcard name

- Issue #2095841: Add MigrationBase methods to enable/disable mail system.

- Issue #2419373: Performance improvement when using Source migrations in combination with MigrateSQLMap

- Issue #2141687: Make error messages include more information when migrating files

**Bug fixes**

- Field sanitization added to prevent possibility of XSS - see security advisory https://security.drupal.org/node/155268.

- Issue #2447115: Mapping editor does not properly save XML mappings

- Issue #2497015: Remapping taxonomy terms breaks term reference import on dependant migrations

- Issue #2488560: MigrateSourceList and MigrateSourceMultiItems getNextRow() stops after only one iteration

- Issue #2446105: Source fields getting reset as 'do not migrate' after mapping and saving

- Issue #2415977: /tmp is hard-coded in migrate_ui

- Issue #2475473: Drush idlist option broken

- Issue #2465387: Unknown option: --stop during migrate-import via Drush

**Important: If you are upgrading from Migrate 2.5 or earlier**

Migration developers will need to add the 'advanced migration information' permission to their roles to continue seeing all the info in the UI they're used to.

Auto-registration (having classes be registered just based on their class name, with no call to registerMigration or definition in hook_migrate_api()) is no longer supported. Registration of classes defined in hook_migrate_api() is no longer automatic - do a drush migrate-register or use the Register button in the UI to register them.

Migration class constructors should now always accept an $arguments array as the first parameter and pass it to its parent. This version does support legacy migrations which pass a group object, or nothing, but these methods are deprecated.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected drupal7-migrate package.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1238486

http://www.nessus.org/u?a278f0ba

http://www.nessus.org/u?5fd355c7

https://www.drupal.org/node/2516678

Plugin Details

Severity: High

ID: 84849

File Name: fedora_2015-11314.nasl

Version: 2.6

Type: local

Agent: unix

Published: 7/20/2015

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:drupal7-migrate, cpe:/o:fedoraproject:fedora:21

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 7/10/2015

Vulnerability Publication Date: 7/10/2015

Reference Information

FEDORA: 2015-11314