Printer, email and PDF versions - Critical - Unsupported - SA-CONTRIB-2022-022

Project machine name: 
print
Date: 
2022-January-25

Update 2022-05-31. A past and new maintainers have created a fix and new releases which include fixes for the security issue that caused the module to be unsupported.

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Image Media Export Import - Critical - Unsupported - SA-CONTRIB-2022-021

Project machine name: 
image_export_import
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Remote Stream Wrapper - Critical - Unsupported - SA-CONTRIB-2022-020

Project machine name: 
remote_stream_wrapper
Date: 
2022-January-25

Update 2022-05-04: Existing maintainers have updated the project to clarify that the module did not contain a security issue that caused the module to be unsupported.

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Vendor Stream Wrapper - Moderately critical - Unsupported - SA-CONTRIB-2022-019

Project machine name: 
vendor_stream_wrapper
Date: 
2022-January-25

This module provides a stream wrapper for files located in the vendor directory. Even when the vendor directory is moved outside the webroot, it allows providing publically accessible URLs to these files.

The module exposes all files that are in the vendor directory, without a site owner's knowledge or intention. This could be undesirable behavior, especially since this module is required as a dependency by other modules.

Edited October 24, 2023 after the project has been re-supported by new maintainers and this advisory metadata affects composer.

Cog - Critical - Unsupported - SA-CONTRIB-2022-018

Project machine name: 
cog
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Media Entity Flickr - Critical - Unsupported - SA-CONTRIB-2022-017

Project machine name: 
media_entity_flickr
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Vocabulary Permissions Per Role - Critical - Access bypass - SA-CONTRIB-2022-016

Project machine name: 
vppr
Date: 
2022-January-25

Update
Maintainers stepped forward, fixed the security issue, and Vocabulary Permissions Per Role is supported again.

The module allows adding to/editing terms of/removing terms from vocabularies per role.

The module did not properly check access for certain operations allowing an unauthorized malicious user to view, modify and delete terms.

Exif - Critical - Remote code execution - SA-CONTRIB-2022-015

Project machine name: 
exif
Date: 
2022-January-25

This module enables you to automatically scan images uploaded to the site to extract their meta data and store it in taxonomy structures.

The module doesn't sufficiently protect against malicious files being used to attack the site.

This vulnerability is mitigated by the fact that an attacker must have permission to upload images to the site.

Business Responsive Theme - Critical - Unsupported - SA-CONTRIB-2022-013

Project machine name: 
business_responsive_theme
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Swiftype integration - Critical - Unsupported - SA-CONTRIB-2022-012

Project machine name: 
swiftype
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Navbar - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-011

Project machine name: 
navbar
Date: 
2022-January-25

This module provides a very simple, mobile-friendly navigation toolbar.

The module doesn't sufficiently check for user-provided input.

This vulnerability is mitigated by the fact that an attacker must have the ability to post content using a text format (like the default "Filtered HTML" format) that won't filter out the exploit code.

Rate - Critical - Unsupported - SA-CONTRIB-2022-010

Project machine name: 
rate
Date: 
2022-January-25

2022-01-31 - a new maintainer has step forward and this module has been updated.

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Expire reset password link - Critical - Unsupported - SA-CONTRIB-2022-009

Project machine name: 
expire_reset_pass_link
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Admin Toolbar Search - Critical - Unsupported - SA-CONTRIB-2022-008

Project machine name: 
admin_toolbar_search
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Colorbox - Critical - Unsupported - SA-CONTRIB-2022-007

Project machine name: 
colorbox
Date: 
2022-January-25

Updated 2022-02-02: New maintainers have volunteered for the project and created new releases which includes fixes for the security issues that caused the module to be unsupported.

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Taxonomy Access Control Lite - Critical - Unsupported - SA-CONTRIB-2022-006

Project machine name: 
tac_lite
Date: 
2022-January-25

Update 2022-03-01. New maintainers have volunteered for the project and created a new release which includes fixes for the 3 security issues that caused the module to be unsupported.

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Prevent anonymous users to access Drupal pages - Critical - Unsupported - SA-CONTRIB-2022-005

Project machine name: 
anonymousredirect
Date: 
2022-January-25

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002

Project machine name: 
drupal
Date: 
2022-January-19

jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life.

Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. In addition to the issue covered by SA-CORE-2022-001, further security vulnerabilities disclosed in jQuery UI 1.13.0 may affect Drupal 7 only:

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2022-001

Project machine name: 
drupal
Date: 
2022-January-19

jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life.

Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issue that may affect Drupal 9 and 7:

jQuery UI Datepicker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-004

Project machine name: 
jquery_ui_datepicker
Date: 
2022-January-19

jQuery UI is a third-party library used by Drupal. The jQuery UI Datepicker module provides the jQuery UI Datepicker library, which is not included in Drupal 9 core.

jQuery UI was previously thought to be end-of-life.

Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issues that may affect site using the jQuery UI Datepicker module:

Wysiwyg - Moderately critical - Cross site scripting - SA-CONTRIB-2022-003

Project machine name: 
wysiwyg
Date: 
2022-January-05

This module enables you to integrate various What-You-See-Is-What-You-Get (WYSIWYG) rich text editors into Drupal fields with text formats allowing markup for easier editing.

The module doesn't sufficiently sanitize user input before attaching a WYSIWYG editor to an input field such as a textarea. If the editor used has an XSS vulnerability this would allow for example a commenter to put specially crafted markup which could trigger the vulnerability when viewed in the editor by an administrator.

Simple OAuth (OAuth2) & OpenID Connect - Moderately critical - Access bypass - SA-CONTRIB-2022-002

Project machine name: 
simple_oauth
Date: 
2022-January-05

This module enables you to implement OAuth 2.0 authentication for Drupal.

The module doesn't sufficiently verify client secret keys for "confidential" OAuth 2.0 clients when using certain grant types. The token refresh and client credentials grants are not affected.

This vulnerability is mitigated by the fact that the vast majority of OAuth 2.0 clients in the wild are public, not confidential. Furthermore, all affected grant types still require users to authenticate to Drupal during the OAuth flow.

Super Login - Critical - Access bypass - SA-CONTRIB-2022-001

Project machine name: 
super_login
Date: 
2022-January-05

This module enables you to login with an email address.

The module doesn't sufficiently check if a user account is active when using email login.

This vulnerability is mitigated by the fact that an attacker must have an account in the website that is blocked.

Mail Login - Moderately critical - Access bypass - SA-CONTRIB-2021-047

Project machine name: 
mail_login
Date: 
2021-December-22

This modules enables users to login via email address.

This module does not sufficiently check user status when authenticating.

Search API Pages - Critical - Cross Site Scripting - SA-CONTRIB-2021-046

Project machine name: 
search_api_page
Date: 
2021-December-08

This module enables you to create simple search pages based on Search API without the use of Views.

The module doesn’t sufficiently escape all variables provided for custom templates.

This vulnerability is mitigated by the fact that the default template provided by the module is not affected.

Webform - Critical - Cross Site Scripting, Access Bypass - SA-CONTRIB-2021-045

Project machine name: 
webform
Date: 
2021-December-08

Access Bypass:

This module enables you to build forms and surveys in Drupal.

The module doesn't sufficiently check access for administrative features for webforms attached to nodes using the Webform Node module. This may reveal submitted data or allow an attacker to modify submitted data. Additionally, for sites with webforms that send emails and store submissions this vulnerability would allow an attacker to use the site as an email relay (i.e. sending arbitrary emails).

Drupal 8 is now end-of-life - PSA-2021-11-30

Date: 
2021-November-30

As of November 17, 2021, the Drupal core version 8 series has reached end-of-life. This means that all releases of Drupal 8 core (with 8.y.x version numbers) and Drupal contributed project releases that are compatible with only Drupal 8 will be marked unsupported as they no longer have security team support.

Drupal 8.0.0 was first released on November 9, 2015. The last version was released on November 17, 2021.

OpenID Connect Microsoft Azure Active Directory client - Moderately critical - Access Bypass - SA-CONTRIB-2021-044

Project machine name: 
openid_connect_windows_aad
Date: 
2021-November-17

This module enables users to authenticate through their Microsoft Azure AD account.

The module does not sufficiently check authorization before updating user profile information in certain non-default configurations. This could lead a user being able to hijack another existing account.

Loft Data Grids - Moderately critical - XML External Entity (XXE) Processing - SA-CONTRIB-2021-043

Project machine name: 
loft_data_grids
Date: 
2021-October-13

This module enables aklump/loft_data_grids to be used as a Drupal module.

Excel support was provided by https://packagist.org/packages/phpoffice/phpexcel, which is abandoned and there are known security vulnerabilities: [CVE-2018-19277]: PHPOffice/PhpSpreadsheet#771. Excel support has since been replaced with the newer https://github.com/PHPOffice/PhpSpreadsheet library.

Linkit - Moderately critical - Cross Site Scripting - SA-CONTRIB-2021-042

Project machine name: 
linkit
Date: 
2021-September-29

Linkit provides an easy interface for internal and external linking with WYSIWYG editors by using an autocomplete field.

It does not sufficiently sanitize user input.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to create or edit an entity bundle.

The Better Mega Menu - Moderately critical - Access bypass - SA-CONTRIB-2021-041

Project machine name: 
tb_megamenu
Date: 
2021-September-22

This module provides an admin interface for creating drop down menus that combine Drupal menu items with rich media content.

This module has a vulnerability whereby users can select blocks as a menu item they don't have permission to view.

The vulnerability is mitigated by the fact that it can only be exploited by an attacker with the "Administer TB Mega Menu" permission.

The Better Mega Menu - Critical - Cross Site Request Forgery - SA-CONTRIB-2021-040

Project machine name: 
tb_megamenu
Date: 
2021-September-22

This module provides an admin interface for creating drop down menus that combine Drupal menu items with rich media content.

The module does not use CSRF tokens to protect routes for saving menu configurations.

This vulnerability can be exploited by an anonymous user.

The Better Mega Menu - Moderately critical - Cross Site Scripting - SA-CONTRIB-2021-039

Project machine name: 
tb_megamenu
Date: 
2021-September-22

This module provides an admin interface for creating drop down menus that combine Drupal menu items with rich media content.

It does not sufficiently sanitize user input such that an admin with permissions to edit a menu may be able to exploit one or more Cross-Site-Scripting (XSS) vulnerabilities.

This vulnerability is mitigated by the fact that an attacker must have permission to administer mega menus and/or create or edit menu links, to inject the XSS.

The Better Mega Menu - Moderately critical - Cross Site Scripting, Information Disclosure, Multiple vulnerabilities - SA-CONTRIB-2021-038

Project machine name: 
tb_megamenu
Date: 
2021-September-22

This module provides an admin interface for creating drop down menus that combine Drupal menu items with rich media content.

The module does not sanitize values for CSS properties that are added by admins and rendered on the front-end, allowing attackers to inject malicious code into the front-end markup.

Domain Group - Critical - Access bypass - SA-CONTRIB-2021-037

Project machine name: 
domain_group
Date: 
2021-September-22

This module enables sites to define a domain from Domain Access that points directly to a group page.

The module doesn't sufficiently manage the access to content administrative paths allowing an attacker to see and take actions on content (nodes) they should be allowed to.

SAML SP 2.0 Single Sign On (SSO) - SAML Service Provider - Moderately critical - Multiple vulnerabilities - SA-CONTRIB-2021-036

Project machine name: 
miniorange_saml
Date: 
2021-September-22

This module provides a solution to authenticate visitors using existing SAML providers.

Certain non-default configurations allow a malicious user to login as any chosen user.

The vulnerability is mitigated by the module's default settings which require the options "Either sign SAML assertions" and "x509 certificate".

Taxonomy Manager - Moderately critical - Access bypass - SA-CONTRIB-2021-035

Project machine name: 
taxonomy_manager
Date: 
2021-September-22

This module provides a powerful interface for managing a taxonomy vocabulary. A vocabulary gets displayed in a dynamic tree view, where parent terms can be expanded to list their nested child terms or can be collapsed.

The module does not take the correct user permissions into account, allowing an attacker to delete and move terms.

The issue is mitigated by the fact that an attacker must have permission to create terms in the targeted vocabulary.

Search API attachments - Critical - Arbitrary PHP code execution - SA-CONTRIB-2021-034

Project machine name: 
search_api_attachments
Date: 
2021-September-22

This module enables you to extract the textual content of files for use on a website, e.g. to display it or use it in search indexes.

The module doesn't sufficiently protect the administrator-defined commands that are executed on the server, which leads to post-authentication remote code execution by a limited set of users.

File Extractor - Critical - Arbitrary PHP code execution - SA-CONTRIB-2021-033

Project machine name: 
file_extractor
Date: 
2021-September-22

This module enables you to extract the textual content of files for use on a website, e.g. to display it or use it in search indexes.

The module doesn't sufficiently protect the administrator-defined commands that are executed on the server, which leads to post-authentication remote code execution by a limited set of users.

Commerce Core - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2021-032

Project machine name: 
commerce
Date: 
2021-September-22

This module provides a system for building an ecommerce solution in their Drupal site.

The module doesn't sufficiently verify access to profile data in certain circumstances.

This vulnerability is mitigated by the fact that an attacker must have permission to perform the checkout operation.

Client-side Hierarchical Select - Moderately critical - Cross-site scripting - SA-CONTRIB-2021-031

Project machine name: 
cshs
Date: 
2021-September-22

The module provides a field widget for selecting taxonomy terms in a hierarchical fashion.

The module doesn't sanitize user input in certain cases, leading to a possible Cross-Site-Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit taxonomy terms to which the widget may apply.

User hash - Moderately critical - Cache poisoning - SA-CONTRIB-2021-030

Project machine name: 
user_hash
Date: 
2021-September-22

This module enables you to create an individual hash for each user. These hashes can be used for authentication instead of the user's password, e.g. for views exporters.

The module doesn't sufficiently invalidate page output when the page_cache module is used.

This vulnerability is mitigated by the fact that an attacker must have a user hash that grants access to specific content and the attack must be timed to the reset of the page cache.

GraphQL - Moderately critical - Access bypass - SA-CONTRIB-2021-029

Project machine name: 
graphql
Date: 
2021-September-15
CVE IDs: 
CVE-2020-13675

This advisory addresses a similar issue to Drupal core - Moderately critical - Access bypass - SA-CORE-2021-008.

The GraphQL module allows file uploads through its HTTP API. The module does not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

This vulnerability is mitigated by four factors:

Entity Embed - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2021-028

Project machine name: 
entity_embed
Date: 
2021-September-15
CVE IDs: 
CVE-2020-13673

This advisory addresses a similar issue to Drupal core - Moderately critical - Cross Site Request Forgery - SA-CORE-2021-006.

The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.

Drupal core - Moderately critical - Access Bypass - SA-CORE-2021-010

Project machine name: 
drupal
Date: 
2021-September-15
CVE IDs: 
CVE-2020-13677

Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass.

Sites that do not have the JSON:API module enabled are not affected.

This advisory is not covered by Drupal Steward.

Drupal core - Moderately critical - Access bypass - SA-CORE-2021-009

Project machine name: 
drupal
Date: 
2021-September-15
CVE IDs: 
CVE-2020-13676

The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data.

Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

This advisory is not covered by Drupal Steward.

Drupal core - Moderately critical - Access bypass - SA-CORE-2021-008

Project machine name: 
drupal
Date: 
2021-September-15
CVE IDs: 
CVE-2020-13675

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

This vulnerability is mitigated by three factors:

Drupal core - Moderately critical - Cross Site Request Forgery - SA-CORE-2021-007

Project machine name: 
drupal
Date: 
2021-September-15
CVE IDs: 
CVE-2020-13674

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues.

Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.

This advisory is not covered by Drupal Steward.

Drupal core - Moderately critical - Cross Site Request Forgery - SA-CORE-2021-006

Project machine name: 
drupal
Date: 
2021-September-15
CVE IDs: 
CVE-2020-13673

The Drupal core Media module allows embedding internal and external media in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed media. In some cases, this could lead to cross-site scripting.

This advisory is not covered by Drupal Steward.

Pages

Subscribe with RSS Subscribe to Security advisories