Closed (fixed)
Project:
Tracking Code [D7]
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Reporter:
Created:
11 Mar 2015 at 11:21 UTC
Updated:
25 Mar 2015 at 18:39 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
fathershawnWe have a client willing to sponsor fixing this issue. If you have specific concerns about the vulnerability, please contact me via my contact form rather than discuss a vulnerability here.
If you have questions about the process, or non-technical concerns about the Security status, please do post them here.
Comment #2
fathershawnHere's the patch
Comment #3
silkogelman commentedtested:
the patch applies perfectly on latest dev
tested with both a fresh Drupal install and an existing install:
all module functionality seems to work fine after the patch.
(managing snippets from UI, the snippets appearing in the source code of the desired pages)
I have NOT tested if it solves the security issue. (I'll leave that for the security team as I don't have that skill set)
Comment #4
grendzy commentedOn behalf of the Drupal Security Team, I've confirmed this patch resolves the CSRF issue. Thanks!
Comment #5
silkogelman commentedAwesome! Thanks guys!
Comment #7
pere orgaUpdated advisory and published the release
Thanks!
Comment #8
pere orgaComment #9
fathershawn