This was originally reported as a private security issue but cleared by the security team for a public issue
- confidential private issue: https://git.drupalcode.org/security/185265-drupal-security/-/work_items/1
(included for reference. Please do not report access denied as an error.)
Problem/Motivation
Nodes, taxonomy terms, and media entities all expose a computed path field. When JSON:API write operations are enabled, any account holding the basic create url aliases permission (not the elevated administer url aliases permission) can PATCH that field. The save handler for this field, PathItem::postSave(), will honor a client-supplied pid (path-alias entity ID) and load/update/delete whatever alias record that ID points to — with no check that the alias actually belongs to the entity being saved.
Steps to reproduce
Minimal setup:
- Enable jsonapi, path, and path_alias.
- Enable JSON:API writes.
- Create a victim node with alias /victim-page.
- Note the victim path alias entity ID, for example 42.
- Create an node2 that the unauthorised user can update.
- Give the unauthorised user create url aliases, but not administer url aliases.
Proposed resolution
When pid is supplied:
- Load the alias entity.
- Verify that $path_alias->getPath() equals '/' . $entity->toUrl()->getInternalPath().
- Verify language compatibility.
- Require update access to the alias entity, or ignore client-supplied pid and resolve the alias by the current entity path only.
Remaining tasks
User interface changes
N/A
Introduced terminology
N/A
API changes
N/A
Data model changes
N/A
Release notes snippet
N/A
Issue fork drupal-3622156
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
mohit_aghera commentedComment #3
mohit_aghera commentedComment #7
quietone commentedShould this be on main? We fix things on main first and then backport.
Comment #8
mohit_aghera commentedComment #9
smustgrave commentedShould this get a CR for a new message that could be shown?