I attach a patch.

Original patch by Francisco José Cruz Romanos, and Peter Wolanin of the Drupal Security Team.

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

grisendo’s picture

grisendo’s picture

Status: Active » Needs review
larowlan’s picture

Issue summary: View changes
larowlan’s picture

Component: image system » field system
Issue tags: +SA-CORE-2013-03

Reroll after SA-CORE-2013-03

larowlan’s picture

Issue summary: View changes
larowlan’s picture

FileSize
499 bytes
scor’s picture

tim.plunkett’s picture

Issue tags: -SA-CORE-2013-03 +SA-CORE-2013-003

Status: Needs review » Needs work

The last submitted patch, 6: image-xss-1892530.4.patch, failed testing.

swentel’s picture

Status: Needs work » Needs review

6: image-xss-1892530.4.patch queued for re-testing.

Status: Needs review » Needs work

The last submitted patch, 6: image-xss-1892530.4.patch, failed testing.

amateescu’s picture

Status: Needs work » Needs review
FileSize
905 bytes

The original patch was correct, we only filter on output, not on regular API calls.

klausi’s picture

Title: XSS in image file description » XSS in image file description (forward port of SA-CORE-2013-003)
Priority: Normal » Critical
Issue tags: +Security improvements

Security issues are critical.

Status: Needs review » Needs work

The last submitted patch, 12: 1892530-12.patch, failed testing.

The last submitted patch, 12: 1892530-12.patch, failed testing.

The last submitted patch, 12: 1892530-12.patch, failed testing.

amateescu’s picture

Status: Needs work » Needs review

12: 1892530-12.patch queued for re-testing.

tim.plunkett’s picture

Status: Needs review » Reviewed & tested by the community

Looks good to me.

webchick’s picture

Status: Reviewed & tested by the community » Fixed

Committed and pushed to 8.x. Thanks!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.