This was originally reported as a private security issue but cleared by the security team for a public issue

Problem/Motivation

Nodes, taxonomy terms, and media entities all expose a computed path field. When JSON:API write operations are enabled, any account holding the basic create url aliases permission (not the elevated administer url aliases permission) can PATCH that field. The save handler for this field, PathItem::postSave(), will honor a client-supplied pid (path-alias entity ID) and load/update/delete whatever alias record that ID points to — with no check that the alias actually belongs to the entity being saved.

Steps to reproduce

Minimal setup:

  1. Enable jsonapi, path, and path_alias.
  2. Enable JSON:API writes.
  3. Create a victim node with alias /victim-page.
  4. Note the victim path alias entity ID, for example 42.
  5. Create an node2 that the unauthorised user can update.
  6. Give the unauthorised user create url aliases, but not administer url aliases.

Proposed resolution

When pid is supplied:
- Load the alias entity.
- Verify that $path_alias->getPath() equals '/' . $entity->toUrl()->getInternalPath().
- Verify language compatibility.
- Require update access to the alias entity, or ignore client-supplied pid and resolve the alias by the current entity path only.

Remaining tasks

User interface changes

N/A

Introduced terminology

N/A

API changes

N/A

Data model changes

N/A

Release notes snippet

N/A

Issue fork drupal-3622156

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

mohit_aghera created an issue. See original summary.

mohit_aghera’s picture

Component: jsonapi.module » path.module
Issue summary: View changes
mohit_aghera’s picture

Issue summary: View changes

mohit_aghera changed the visibility of the branch 3622156-path.pid-reference-allows to hidden.

quietone’s picture

Version: 11.4.x-dev » main

Should this be on main? We fix things on main first and then backport.

mohit_aghera’s picture

Status: Active » Needs review
smustgrave’s picture

Should this get a CR for a new message that could be shown?