Updated: Comment #0
Problem/Motivation
Part of SA-CORE-2013-003
The Overlay module displays administrative pages as a layer over the current page (using JavaScript), rather than replacing the page in the browser window. The Overlay module did not sufficiently validate URLs prior to displaying their contents, leading to an open redirect vulnerability.
Proposed resolution
Forward port patch
Remaining tasks
Review
User interface changes
None
API changes
?
Related Issues
None
Original patch by Heine Deelstra of the Drupal Security Team
| Comment | File | Size | Author |
|---|---|---|---|
| overlay-redirect.1.patch | 1.23 KB | larowlan |
Comments
Comment #1
larowlanComment #2
larowlanComment #4
larowlanComment #5
scor commentedComment #6
amateescu commentedoverlay-redirect.1.patch queued for re-testing.
Comment #9
amateescu commentedoverlay-redirect.1.patch queued for re-testing.
Comment #10
amateescu commentedSA followups are critical, marking as such. Also, this is ready to go.
Comment #11
webchickCommitted and pushed to 8.x. Thanks!