Webform Report - Critical - Unsupported - SA-CONTRIB-2019-086

Project machine name: 
webform_report
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Nodequeue - Critical - Cross Site Scripting - SA-CONTRIB-2019-085

Project machine name: 
nodequeue
Date: 
2019-November-13

Updated November 22.

This module enables you to collect nodes in an arbitrarily ordered list.

Nodequeue's JavaScript can be leveraged to insert HTML from attacker-controlled JSON data. This is exploitable if user-submitted "Filtered HTML" content is displayed on a page where nodequeue.js is loaded.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "manipulate queues".

Taxonomy CSV import/export - Moderately critical - Information disclosure - SA-CONTRIB-2019-084

Project machine name: 
taxonomy_csv
Date: 
2019-November-13

Updated January 9th, 2020

This module enables you to import taxonomy terms from different sources, including a text area, a file upload or a file present in the web server.

The module doesn't sufficiently validate user input when providing a local
filename to import.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "import taxonomy by csv".

Original advisory:

Feeds JSONPath Parser - Critical - Unsupported - SA-CONTRIB-2019-083

Project machine name: 
feeds_jsonpath_parser
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Update:

Field Slideshow - Less critical - Cross site scripting - SA-CONTRIB-2019-082

Project machine name: 
field_slideshow
Date: 
2019-November-13

This module enables you to output a field as a slideshow.

The module doesn't sufficiently filter strings added to the fields leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have the ability to create content which is output as a slideshow.

Bugsnag - Critical - Unsupported - SA-CONTRIB-2019-081

Project machine name: 
bugsnag
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Noggin - Critical - Unsupported - SA-CONTRIB-2019-080

Project machine name: 
noggin
Date: 
2019-November-13

Update - 2021-01-22

This maintainer has fixed this security issue. Please install https://www.drupal.org/project/noggin/releases/7.x-1.2 to resolve the issue.

Bypass Form Validations - Critical - Unsupported - SA-CONTRIB-2019-079

Project machine name: 
bypass_form_validations
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Nexus Theme - Critical - Unsupported - SA-CONTRIB-2019-078

Project machine name: 
nexus
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Frequently Asked Questions - Critical - Unsupported - SA-CONTRIB-2019-077

Project machine name: 
faq
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Administration Views - Moderately critical - Access bypass - SA-CONTRIB-2019-076

Project machine name: 
admin_views
Date: 
2019-November-13

This module replaces administrative overview/listing pages with actual views for superior usability.

The module doesn't sufficiently check user access when using the "Menu system path" access handler on a Views displays other than "System".

Update:
This project had been unsupported due to this advisory. The security issue is now fixed and the project is supported again.

Open Social - Critical - Insecure Session Management - SA-CONTRIB-2019-075

Project machine name: 
social
Date: 
2019-November-06

Open Social is a Drupal distribution for online communities. The included social_magic_login module doesn't sufficiently validate magic login URLs for user accounts that do not have a local password, but login via external systems. The lack of validation makes it possible for an adversary to forge valid login URLs and login to such an account.

This vulnerability is mitigated by the fact the module social_magic_login needs to be enabled.

Booking and Availability Management Tools for Drupal - Moderately critical - Access Bypass - SA-CONTRIB-2019-074

Project machine name: 
bat
Date: 
2019-October-16

The Bat module provides a foundation through which a wide range of availability management, reservation and booking use cases can be addressed.

The routes used to view events don't sufficiently guard access for non-privileged users. Specifically, a user with the 'View own' permission for bat events can view others' events as well.

MaxLength - Moderately critical - Cross Site Scripting - SA-CONTRIB-2019-073

Project machine name: 
maxlength
Date: 
2019-October-09

This module enables you to set a maximum length allowed on text fields and indicate how many characters are left.

The module doesn't sufficiently filter strings leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact the malicious script will not be triggered in the browser of UID 1 nor any user with "Bypass maxlength setting".

Localization update - Moderately critical - Insecure server configuration - SA-CONTRIB-2019-072

Project machine name: 
l10n_update
Date: 
2019-October-02

This module enables you to automatically download and update the site's interface translation by fetching them from localize.drupal.org or any other Localization server.

The module doesn't sufficiently protect the directory it stores translation files in. It's conventional for directories which may be writeable to be protected by a .htaccess file to prevent malicious PHP files placed within them being executed by the webserver. This vulnerability is mitigated by the fact that an attacker typically wouldn't be able to place a malicious file in the module's storage directory.

Simple AMP (Accelerated Mobile Pages) - Moderately critical - Access bypass - SA-CONTRIB-2019-071

Project machine name: 
simple_amp
Date: 
2019-October-02

This module allows display of a site's content in AMP format.

The module doesn't sufficiently check access on unpublished or restricted content.

Ubercart - Moderately critical - Cross site scripting - SA-CONTRIB-2019-070

Project machine name: 
ubercart
Date: 
2019-October-02

The Ubercart module provides a shopping cart and e-commerce features for Drupal.

The order module doesn't sufficiently sanitize user input when displayed on an invoice leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit orders".

Gutenberg - Critical - Access bypass - SA-CONTRIB-2019-069

Project machine name: 
gutenberg
Date: 
2019-September-25

This module provides a new UI experience for node editing - Gutenberg editor.

The routes used by the Gutenberg editor lack proper permissions allowing untrusted users to view and modify some content they should not be able to view or modify.

Permissions by Term - Moderately critical - Access bypass - SA-CONTRIB-2019-068

Project machine name: 
permissions_by_term
Date: 
2019-September-25

This module enables you to control access to content based on taxonomy terms. The module doesn't sufficiently check if a given entity should be access controlled, defaulting to allowing access even to unpublished nodes.

The vulnerability is mitigated by the fact that the submodule Permissions by Entity must also be enabled.

TableField - Moderately critical - Access bypass - SA-CONTRIB-2019-067

Project machine name: 
tablefield
Date: 
2019-September-18

This module allows you to attach tabular data to an entity.

There is insufficient access checking for users with the ability to "Export Tablefield Data as CSV". They can export data from unpublished nodes or otherwise inaccessible entities.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Export Tablefield Data as CSV".

Create user permission - Critical - Access bypass - SA-CONTRIB-2019-066

Project machine name: 
create_user_permission
Date: 
2019-September-18

This module enables you to have a separate permission only for creating users.

The module doesn't respect Drupal's setting for "Who can register accounts?" when set to "Visitors, but administrator approval is required".

When this option is chosen, the module overrides the setting, and makes it possible to register accounts with no approval.

This vulnerability can be mitigated by having other settings in place for account registration, such as requiring email verification for new accounts, or permitting account creation for "Administrators only".

Various Third-Party Vulnerabilities - PSA-2019-09-04

Date: 
2019-September-04

In June of 2011, the Drupal Security Team issued Public Service Advisory PSA-2011-002 - External libraries and plugins.

8 years later that is still the policy of the Drupal Security team. As Drupal core and modules leverage third-party code more and more it seems like an important time to remind site owners that they are responsible for monitoring security of third-party libraries. Here is the advice from 2011 which is even more relevant today:

Imagecache External - Critical - Insecure session token management - SA-CONTRIB-2019-065

Project machine name: 
imagecache_external
Date: 
2019-August-21

This module that allows you to store external images on your server and apply your own Image Styles.

The module exposes cookies to external sites when making external image requests.

This vulnerability is mitigated by using the whitelisted host feature to restrict external image requests from trusted sources.

Forms Steps - Critical - Access bypass - SA-CONTRIB-2019-064

Project machine name: 
forms_steps
Date: 
2019-August-14

Forms Steps provides an UI to create form workflows using form modes. It creates quick and configurable multisteps forms.

The module doesn't sufficiently check user permissions to access its workflows entities that allows to see any entities that have been created through the different steps of its multistep forms.

This vulnerability is mitigated by the fact that you have to know the Forms Steps URL to create a content linked to the flow. Also, all created content is very hard to edit through the same flow as you have to know the URL and the linked hash to the content.

External Links Filter - Moderately critical - Open Redirect Vulnerability - SA-CONTRIB-2019-063

Project machine name: 
elf
Date: 
2019-August-14

The External Link Filter module provides an input filter that replaces external links by a local link that redirects to the target URL.

The module did not have protection for the Redirect URL to go where content authors intended.

Super Login - Moderately critical - Cross site scripting - SA-CONTRIB-2019-062

Project machine name: 
super_login
Date: 
2019-August-14

This module improves the Drupal login page with the new features and layout.

The module doesn't sufficiently filter input text in the administration pages text configuration inputs. For example, the login text field.

The vulnerability is mitigated by the fact it can only be exploited by a user with the "Administer super login" permission.

scroll to top - Moderately critical - Cross site scripting - SA-CONTRIB-2019-061

Project machine name: 
scroll_to_top
Date: 
2019-August-14

The Scroll To Top module enables you to have an animated scroll to top link in the bottom of the node.

The module does not sufficiently filter configuration text leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer scroll to top".

Existing Values Autocomplete Widget - Critical - Access bypass - SA-CONTRIB-2019-060

Project machine name: 
existing_values_autocomplete_widget
Date: 
2019-July-24

This module provides an autocomplete widget for text fields that suggests all existing (previously entered) values for that field.

The module doesn't sufficiently check for proper access permission before returning autocomplete results.

This vulnerability is mitigated by the fact that an attacker must know the route to the autocomplete callback controller though this is easily known.

Facebook Messenger Customer Chat Plugin - Critical - Access bypass - SA-CONTRIB-2019-059

Project machine name: 
fb_messenger_customer_chat_plugin
Date: 
2019-July-24

The Facebook Messenger Customer Chat Plugin module enables you to add the Facebook Messenger Customer Chat Plugin to your Drupal site.

The module doesn't require user permissions on the admin page.

Metatag - Moderately critical - Information disclosure - SA-CONTRIB-2019-058

Project machine name: 
metatag
Date: 
2019-July-24

This module enables you to customize meta tags to help with a site's search engine ranking and improve the display of page summaries when shared on social networks.

The module doesn't sufficiently check for a site being in maintenance mode.

This vulnerability is mitigated by the fact that the site must be configured to disallow access to certain content, and must be put into maintenance mode.

Drupal core - Critical - Access bypass - SA-CORE-2019-008

Project machine name: 
drupal
Date: 
2019-July-17
CVE IDs: 
CVE-2019-6342

In Drupal 8.7.4, when the experimental Workspaces module is enabled, an access bypass condition is created.

This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

Drupal 8.7.3 and earlier, Drupal 8.6.x and earlier, and Drupal 7.x are not affected.

Meta tags quick - Moderately critical - Cross Site Scripting - SA-CONTRIB-2019-057

Project machine name: 
metatags_quick
Date: 
2019-July-17

Metatags quick is a module that manages meta tags (tags that appear in HTML's head section) as Drupal 7 fields.
Administration page of metatags quick does not sanitize the output of blocks that appear on the same page. This allows an attacker to inject malicious JavaScript in block markup.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer blocks".

ImageCache Actions - Critical - Multiple Vulnerabilities - SA-CONTRIB-2019-056

Project machine name: 
imagecache_actions
Date: 
2019-July-17

The imagecache actions module defines a number of additional image effects that can be used to create image styles. The "Image styles admin" sub module provides additional functionality to duplicate, export and import image styles. The module uses unserialize() to import image styles into another site where unserialize() is known to have security issues when processing potentially unsafe input.

This vulnerability is mitigated by the fact that the "Image styles admin" sub module must be enabled and an attacker must have a role with the permission "'administer image styles'".

Custom Permissions - Critical - Access bypass - SA-CONTRIB-2019-055

Project machine name: 
config_perms
Date: 
2019-July-10

This module enables you to add and manage additional custom permissions through the administration UI.

The module doesn't sufficiently check for the proper access permissions to this page.

This vulnerability is mitigated by the fact that an attacker must know the route of the Custom Permissions administration form though this is easily known.

Advanced Forum - Critical - Cross Site Scripting - SA-CONTRIB-2019-054

Project machine name: 
advanced_forum
Date: 
2019-June-26

Advanced Forum builds on and enhances Drupal's core forum module. When used in combination with other Drupal contributed modules, many of which are automatically used by Advanced Forum, you can achieve much of what stand alone software provides.

The module doesn't sufficiently sanitise user input in specific circumstances. It is not possible to disable the vulnerable functionality.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create forum content.

Easy Breadcrumb - Critical - Cross Site Scripting - SA-CONTRIB-2019-053

Project machine name: 
easy_breadcrumb
Date: 
2019-June-19

This module enables you to use the current URL (path alias) and the current page's title to automatically extract the breadcrumb's segments and its respective links then show them as breadcrumbs on your website.

The module doesn't sufficiently sanitise user input in certain circumstances.

This vulnerability does not require any permissions but can be mitigated by un-checking the 'Allow HTML tags in breadcrumb text' setting (enabled by default). In some cases browsers' built-in XSS protection may prevent exploitation.

Universally Unique IDentifier - Moderately critical - Access bypass - SA-CONTRIB-2019-052

Project machine name: 
uuid
Date: 
2019-May-29

This module provides an API for adding universally unique identifiers (UUID) to Drupal objects, most notably entities.

The module has a privilege escalation vulnerability when it's used in combination with Services+REST server.

This vulnerability is mitigated by the fact that an attacker must authenticate to the site, services module must be configured on the site and the user update resource enabled.

TableField - Moderately critical - Access bypass and Cross Site Scripting - SA-CONTRIB-2019-051

Project machine name: 
tablefield
Date: 
2019-May-29

This module allows you to attach tabular data to an entity.

Access bypass

There's no access check for users with an "Export Tablefield Data as CSV". They can export data from unpublished nodes or otherwise inaccessible entities.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission 'Export Tablefield Data as CSV'.

XSS

When "Raw data (JSON or XML)" is used in the field's Display settings, it doesn't sanitize JSON output before passing it on to be rendered.

Menu Item Extras - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2019-050

Project machine name: 
menu_item_extras
Date: 
2019-May-22

This module enables you to handle fields for Custom Menu Links.
The module doesn't sufficiently check requests to one of the module controllers if the user has permission 'administer menu'.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to create content.

Workflow - Moderately critical - Cross Site Scripting - SA-CONTRIB-2019-049

Project machine name: 
workflow
Date: 
2019-May-22

The Workflow module enables you to create arbitrary Workflows, and assign them to Entities.
The module doesn't sufficiently escape HTML in the field settings leading to a Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer nodes" and "administer workflow".

Multiple Registration - Critical - Access bypass - SA-CONTRIB-2019-048

Project machine name: 
multiple_registration
Date: 
2019-May-15

This module enables you to use special routes for user registration with special roles and custom field sets defined for the role.

The module doesn't sufficiently check which user roles can be registered under the scenario when the user tries to register the user with the administrator role.

This vulnerability is mitigated on sites where account approval is required as the user starts as blocked but still gets the "Administrator" role.

Opigno Learning path - Moderately critical - Access bypass - SA-CONTRIB-2019-047

Project machine name: 
opigno_learning_path
Date: 
2019-May-15

In certain configuration cases, when a learning path is configured as semi-private, anonymous users are allowed to join a learning path when they should not.

Opigno forum - Less critical - Access bypass - SA-CONTRIB-2019-046

Project machine name: 
opigno_forum
Date: 
2019-May-15

In certain circumstances it is possible that certain forum information is available to unprivileged users because the access check is done with node access instead of grants.

This vulnerability is mitigated by the fact that the module itself does not disclose information but only if there are listings such as views where the site builder / developer has not taken this into account.

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2019-007

Project machine name: 
drupal
Date: 
2019-May-08
CVE IDs: 
CVE-2019-11831

This security release fixes third-party dependencies included in or required by Drupal core. As described in TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor:

In order to intercept file invocations like file_exists or stat on compromised Phar archives the base name has to be determined and checked before allowing to be handled by PHP Phar stream handling. [...]

Drupal 7 and 8 release on May 8th, 2019 - PSA-2019-05-07

Date: 
2019-May-07

The Drupal Security Team will be coordinating a security release for Drupal 7 and 8 this week on Wednesday, May 8th, 2019.

We are issuing this PSA in advance because according to the regular security release window schedule, May 8th would not typically be a core security window.

This release is rated as moderately critical.

The Drupal 7 and 8 core release will be made between 16:00 – 21:00 UTC (noon – 5:00pm Eastern).

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-006

Project machine name: 
drupal
Date: 
2019-April-17
CVE IDs: 
CVE-2019-11358

The jQuery project released version 3.4.0, and as part of that, disclosed a security vulnerability that affects all prior versions. As described in their release notes:

jQuery 3.4.0 includes a fix for some unintended behavior when using jQuery.extend(true, {}, ...). If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. This fix is included in jQuery 3.4.0, but patch diffs exist to patch previous jQuery versions.

Drupal core - Moderately critical - Multiple Vulnerabilities - SA-CORE-2019-005

Project machine name: 
drupal
Date: 
2019-April-17

This security release fixes third-party dependencies included in or required by Drupal core.

TableField - Critical - Remote Code Execution - SA-CONTRIB-2019-045

Project machine name: 
tablefield
Date: 
2019-April-17

This module allows you to attach tabular data to an entity.

The module doesn't sufficiently determine that the data being unserialized is the contents of a tablefield when users request a CSV export, which could lead to Remote Code Execution via Object Injection.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission 'export tablefield', and be able to insert a payload into an entity's field.

Stage File Proxy - Less critical - Denial of Service - SA-CONTRIB-2019-044

Project machine name: 
stage_file_proxy
Date: 
2019-April-17

Stage File Proxy is a general solution for getting production files on a development server on demand.

The module doesn't sufficiently validate requested urls, allowing an attacker to send repeated requests for files that do not exist which could exhaust resources on the server where Stage File Proxy is installed.

Services - Less critical - Access bypass - SA-CONTRIB-2019-043

Project machine name: 
services
Date: 
2019-April-03

This module provides a standardized solution for building API's so that external clients can communicate with Drupal.

The Services module has an access bypass vulnerability in its "attach_file" resource that allows users who have access to create or update nodes that include file fields to arbitrarily reference files they do not have access to, which can expose private files.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit a node.

Pages

Subscribe with RSS Subscribe to Security advisories