External Links Filter - Moderately critical - Open Redirect Vulnerability - SA-CONTRIB-2019-063

Project machine name: 
elf
Date: 
2019-August-14

The External Link Filter module provides an input filter that replaces external links by a local link that redirects to the target URL.

The module did not have protection for the Redirect URL to go where content authors intended.

Super Login - Moderately critical - Cross site scripting - SA-CONTRIB-2019-062

Project machine name: 
super_login
Date: 
2019-August-14

This module improves the Drupal login page with the new features and layout.

The module doesn't sufficiently filter input text in the administration pages text configuration inputs. For example, the login text field.

The vulnerability is mitigated by the fact it can only be exploited by a user with the "Administer super login" permission.

scroll to top - Moderately critical - Cross site scripting - SA-CONTRIB-2019-061

Project machine name: 
scroll_to_top
Date: 
2019-August-14

The Scroll To Top module enables you to have an animated scroll to top link in the bottom of the node.

The module does not sufficiently filter configuration text leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer scroll to top".

Existing Values Autocomplete Widget - Critical - Access bypass - SA-CONTRIB-2019-060

Project machine name: 
existing_values_autocomplete_widget
Date: 
2019-July-24

This module provides an autocomplete widget for text fields that suggests all existing (previously entered) values for that field.

The module doesn't sufficiently check for proper access permission before returning autocomplete results.

This vulnerability is mitigated by the fact that an attacker must know the route to the autocomplete callback controller though this is easily known.

Facebook Messenger Customer Chat Plugin - Critical - Access bypass - SA-CONTRIB-2019-059

Project machine name: 
fb_messenger_customer_chat_plugin
Date: 
2019-July-24

The Facebook Messenger Customer Chat Plugin module enables you to add the Facebook Messenger Customer Chat Plugin to your Drupal site.

The module doesn't require user permissions on the admin page.

Metatag - Moderately critical - Information disclosure - SA-CONTRIB-2019-058

Project machine name: 
metatag
Date: 
2019-July-24

This module enables you to customize meta tags to help with a site's search engine ranking and improve the display of page summaries when shared on social networks.

The module doesn't sufficiently check for a site being in maintenance mode.

This vulnerability is mitigated by the fact that the site must be configured to disallow access to certain content, and must be put into maintenance mode.

Drupal core - Critical - Access bypass - SA-CORE-2019-008

Project machine name: 
drupal
Date: 
2019-July-17
CVE IDs: 
CVE-2019-6342

In Drupal 8.7.4, when the experimental Workspaces module is enabled, an access bypass condition is created.

This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

Drupal 8.7.3 and earlier, Drupal 8.6.x and earlier, and Drupal 7.x are not affected.

Meta tags quick - Moderately critical - Cross Site Scripting - SA-CONTRIB-2019-057

Project machine name: 
metatags_quick
Date: 
2019-July-17

Metatags quick is a module that manages meta tags (tags that appear in HTML's head section) as Drupal 7 fields.
Administration page of metatags quick does not sanitize the output of blocks that appear on the same page. This allows an attacker to inject malicious JavaScript in block markup.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer blocks".

ImageCache Actions - Critical - Multiple Vulnerabilities - SA-CONTRIB-2019-056

Project machine name: 
imagecache_actions
Date: 
2019-July-17

The imagecache actions module defines a number of additional image effects that can be used to create image styles. The "Image styles admin" sub module provides additional functionality to duplicate, export and import image styles. The module uses unserialize() to import image styles into another site where unserialize() is known to have security issues when processing potentially unsafe input.

This vulnerability is mitigated by the fact that the "Image styles admin" sub module must be enabled and an attacker must have a role with the permission "'administer image styles'".

Custom Permissions - Critical - Access bypass - SA-CONTRIB-2019-055

Project machine name: 
config_perms
Date: 
2019-July-10

This module enables you to add and manage additional custom permissions through the administration UI.

The module doesn't sufficiently check for the proper access permissions to this page.

This vulnerability is mitigated by the fact that an attacker must know the route of the Custom Permissions administration form though this is easily known.

Advanced Forum - Critical - Cross Site Scripting - SA-CONTRIB-2019-054

Project machine name: 
advanced_forum
Date: 
2019-June-26

Advanced Forum builds on and enhances Drupal's core forum module. When used in combination with other Drupal contributed modules, many of which are automatically used by Advanced Forum, you can achieve much of what stand alone software provides.

The module doesn't sufficiently sanitise user input in specific circumstances. It is not possible to disable the vulnerable functionality.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create forum content.

Easy Breadcrumb - Critical - Cross Site Scripting - SA-CONTRIB-2019-053

Project machine name: 
easy_breadcrumb
Date: 
2019-June-19

This module enables you to use the current URL (path alias) and the current page's title to automatically extract the breadcrumb's segments and its respective links then show them as breadcrumbs on your website.

The module doesn't sufficiently sanitise user input in certain circumstances.

This vulnerability does not require any permissions but can be mitigated by un-checking the 'Allow HTML tags in breadcrumb text' setting (enabled by default). In some cases browsers' built-in XSS protection may prevent exploitation.

Universally Unique IDentifier - Moderately critical - Access bypass - SA-CONTRIB-2019-052

Project machine name: 
uuid
Date: 
2019-May-29

This module provides an API for adding universally unique identifiers (UUID) to Drupal objects, most notably entities.

The module has a privilege escalation vulnerability when it's used in combination with Services+REST server.

This vulnerability is mitigated by the fact that an attacker must authenticate to the site, services module must be configured on the site and the user update resource enabled.

TableField - Moderately critical - Access bypass and Cross Site Scripting - SA-CONTRIB-2019-051

Project machine name: 
tablefield
Date: 
2019-May-29

This module allows you to attach tabular data to an entity.

Access bypass

There's no access check for users with an "Export Tablefield Data as CSV". They can export data from unpublished nodes or otherwise inaccessible entities.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission 'Export Tablefield Data as CSV'.

XSS

When "Raw data (JSON or XML)" is used in the field's Display settings, it doesn't sanitize JSON output before passing it on to be rendered.

Menu Item Extras - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2019-050

Project machine name: 
menu_item_extras
Date: 
2019-May-22

This module enables you to handle fields for Custom Menu Links.
The module doesn't sufficiently check requests to one of the module controllers if the user has permission 'administer menu'.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to create content.

Workflow - Moderately critical - Cross Site Scripting - SA-CONTRIB-2019-049

Project machine name: 
workflow
Date: 
2019-May-22

The Workflow module enables you to create arbitrary Workflows, and assign them to Entities.
The module doesn't sufficiently escape HTML in the field settings leading to a Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer nodes" and "administer workflow".

Multiple Registration - Critical - Access bypass - SA-CONTRIB-2019-048

Project machine name: 
multiple_registration
Date: 
2019-May-15

This module enables you to use special routes for user registration with special roles and custom field sets defined for the role.

The module doesn't sufficiently check which user roles can be registered under the scenario when the user tries to register the user with the administrator role.

This vulnerability is mitigated on sites where account approval is required as the user starts as blocked but still gets the "Administrator" role.

Opigno Learning path - Moderately critical - Access bypass - SA-CONTRIB-2019-047

Project machine name: 
opigno_learning_path
Date: 
2019-May-15

In certain configuration cases, when a learning path is configured as semi-private, anonymous users are allowed to join a learning path when they should not.

Opigno forum - Less critical - Access bypass - SA-CONTRIB-2019-046

Project machine name: 
opigno_forum
Date: 
2019-May-15

In certain circumstances it is possible that certain forum information is available to unprivileged users because the access check is done with node access instead of grants.

This vulnerability is mitigated by the fact that the module itself does not disclose information but only if there are listings such as views where the site builder / developer has not taken this into account.

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2019-007

Project machine name: 
drupal
Date: 
2019-May-08
CVE IDs: 
CVE-2019-11831

This security release fixes third-party dependencies included in or required by Drupal core. As described in TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor:

In order to intercept file invocations like file_exists or stat on compromised Phar archives the base name has to be determined and checked before allowing to be handled by PHP Phar stream handling. [...]

Drupal 7 and 8 release on May 8th, 2019 - PSA-2019-05-07

Date: 
2019-May-07

The Drupal Security Team will be coordinating a security release for Drupal 7 and 8 this week on Wednesday, May 8th, 2019.

We are issuing this PSA in advance because according to the regular security release window schedule, May 8th would not typically be a core security window.

This release is rated as moderately critical.

The Drupal 7 and 8 core release will be made between 16:00 – 21:00 UTC (noon – 5:00pm Eastern).

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-006

Project machine name: 
drupal
Date: 
2019-April-17
CVE IDs: 
CVE-2019-11358

The jQuery project released version 3.4.0, and as part of that, disclosed a security vulnerability that affects all prior versions. As described in their release notes:

jQuery 3.4.0 includes a fix for some unintended behavior when using jQuery.extend(true, {}, ...). If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. This fix is included in jQuery 3.4.0, but patch diffs exist to patch previous jQuery versions.

Drupal core - Moderately critical - Multiple Vulnerabilities - SA-CORE-2019-005

Project machine name: 
drupal
Date: 
2019-April-17

This security release fixes third-party dependencies included in or required by Drupal core.

TableField - Critical - Remote Code Execution - SA-CONTRIB-2019-045

Project machine name: 
tablefield
Date: 
2019-April-17

This module allows you to attach tabular data to an entity.

The module doesn't sufficiently determine that the data being unserialized is the contents of a tablefield when users request a CSV export, which could lead to Remote Code Execution via Object Injection.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission 'export tablefield', and be able to insert a payload into an entity's field.

Stage File Proxy - Less critical - Denial of Service - SA-CONTRIB-2019-044

Project machine name: 
stage_file_proxy
Date: 
2019-April-17

Stage File Proxy is a general solution for getting production files on a development server on demand.

The module doesn't sufficiently validate requested urls, allowing an attacker to send repeated requests for files that do not exist which could exhaust resources on the server where Stage File Proxy is installed.

Services - Less critical - Access bypass - SA-CONTRIB-2019-043

Project machine name: 
services
Date: 
2019-April-03

This module provides a standardized solution for building API's so that external clients can communicate with Drupal.

The Services module has an access bypass vulnerability in its "attach_file" resource that allows users who have access to create or update nodes that include file fields to arbitrarily reference files they do not have access to, which can expose private files.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit a node.

Module Filter - Moderately critical - Cross site scripting - SA-CONTRIB-2019-042

Project machine name: 
module_filter
Date: 
2019-March-27

This module enables you to filter the list of modules on the admin modules page, and organizes packages into vertical tabs.

The module doesn't sufficiently escape HTML under the scenario leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that the attacker must have access to input filtered html that will be included on the modules administration page e.g. in a block (this configuration is not common). Further, the Module Filter vertical tabs setting must be enabled.

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004

Project machine name: 
drupal
Date: 
2019-March-20
CVE IDs: 
CVE-2019-6341

Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

Back To Top - Moderately critical - Cross Site Scripting - SA-CONTRIB-2019-040

Project machine name: 
back_to_top
Date: 
2019-March-20

This module enables you to add a button that hovers in the bottom of your screen and allows users to smoothly scroll up the page using jQuery.

The module doesn't sufficiently sanitize the code that gets printed on pages leading to a Cross Site Scripting (XSS) issue.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access backtotop settings".

AddToAny Share Buttons - Moderately critical - Cross Site Scripting - SA-CONTRIB-2019-039

Project machine name: 
addtoany
Date: 
2019-March-20

This module enables you to add social media share buttons on your website to its content and pages.

The module doesn't sufficiently mark its administration permission restricted, allowing cross site scripting vulnerabilities to users who have access to its admin settings.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer addtoany".

This advisory was edited on March 25th to add the affected 8.x-1.11 release.

Simple hierarchical select - Moderately critical - Cross site request forgery - SA-CONTRIB-2019-038

Project machine name: 
shs
Date: 
2019-March-13

Simple hierarchical select defines a new form widget for taxonomy fields to select a term by "browsing" through the vocabularies hierarchy. It also allows users to create new taxonomy terms using its widget directly in the node form.

Video - Critical - Remote Code Execution - SA-CONTRIB-2019-037

Project machine name: 
video
Date: 
2019-March-13

This module provides a field where editors can add videos to their content and this module offers functionality to transcode these videos to different sizes and formats.

The module doesn't sufficiently sanitize some user input on administrative forms.

Views (for Drupal 7) - Less critical - Cross site scripting - SA-CONTRIB-2019-036

Project machine name: 
views
Date: 
2019-March-13

This module enables you to create customized lists of data.

The module doesn't sufficiently sanitize certain field types, leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that a view must display a field with the format "Full data (serialized)" and an attacker must have the ability to store malicious markup in that field.

Views (for Drupal 7) - Moderately critical - Information disclosure - SA-CONTRIB-2019-035

Project machine name: 
views
Date: 
2019-March-13

This module enables you to create customized lists of data.

The module doesn't sufficiently build queries when used with exposed filters, leading to a possible information disclosure vulnerability in certain rare circumstances.

This vulnerability is mitigated by the fact that a view must have an exposed filter on a field that is used on multiple entity types, both of which are included in the view.

Views (for Drupal 7) - Moderately critical - Information Disclosure - SA-CONTRIB-2019-034

Project machine name: 
views
Date: 
2019-March-13

This module enables you to create customized lists of data.

The module doesn't sufficiently protect against argument definitions failing.

This vulnerability is mitigated by the fact that a view must have custom PHP code used as a field validator.

EU Cookie Compliance (GDPR Compliance) - Critical - Cross site scripting - SA-CONTRIB-2019-033

Project machine name: 
eu_cookie_compliance
Date: 
2019-March-06

This module addresses the General Data Protection Regulation (GDPR) that came into effect 25th May 2018, and the EU Directive on Privacy and Electronic Communications from 2012. It provides a banner where you can gather consent from the user when the website stores cookies on their computer or otherwise handles their personal information.

Ubercart - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2019-032

Project machine name: 
ubercart
Date: 
2019-March-06

The Ubercart module provides a shopping cart and e-commerce features for Drupal.

The taxes module doesn't sufficiently protect the tax rate cloning feature. A malicious user could trick a store administrator into duplicating an existing tax rate by getting them to visit a specially-crafted URL.

Drupal voor Gemeenten - Moderately critical - Access Bypass - SA-CONTRIB-2019-031

Project machine name: 
dvg
Date: 
2019-March-06

The DvG distrubition contains the feature module dvg_domains to support multiple domains.

When the dvg_domains feature module is enabled, anonymous users are able to access some administration pages and change the settings exposed on those pages.

This issue can be mitigated by disabling the dvg_domains module.

Facets - Moderately critical - Cross site scripting - SA-CONTRIB-2019-030

Project machine name: 
facets
Date: 
2019-February-27

This module enables you to create facet-filters for results of a search query and exposes them as blocks

The module doesn't sufficiently escape HTML under the scenario leading to a Cross Site Scripting (XSS) vulnerability.

Rabbit Hole - Moderately critical - Access bypass - SA-CONTRIB-2019-029

Project machine name: 
rabbit_hole
Date: 
2019-February-27

The Rabbit Hole module allows administrators to control what should happen when a regular user tries to view an entity at its own page; for example, it may deliver a 403 Access Denied or 404 Page Not Found response, or redirect the user to another path.

The module doesn't respect the Rabbit Hole settings when an entity is being requested with a certain header. This could lead to certain data being exposed even if it shouldn't be. The vulnerability is mitigated by the fact that the user also needs permission to view the content being requested.

Context - Moderately critical - Cross site scripting - SA-CONTRIB-2019-028

Project machine name: 
context
Date: 
2019-February-27

This module enables you to manage contextual conditions and reactions for different portions of your site.

The module doesn't sufficiently sanitize user output when displayed leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have the ability to store malicious markup in the site (e.g. permission to create a node with a field that accepts "filtered html").

Path Breadcrumbs - Moderately critical - Cross site scripting - SA-CONTRIB-2019-027

Project machine name: 
path_breadcrumbs
Date: 
2019-February-27

This module enables you to configure breadcrumbs for any Drupal page.

This module doesn't properly sanitize custom breadcrumb configuration in all cases, leading to an XSS vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer Path Breadcrumbs".

Services - Critical - SQL Injection - SA-CONTRIB-2019-026

Project machine name: 
services
Date: 
2019-February-27

This module provides a standardized solution for building API's so that external clients can communicate with Drupal.

The module doesn't sufficiently sanitize user input for entity index resources thus allowing SQL Injection attacks.

This vulnerability is mitigated by the fact that the Drupal 7 site must have an "index" resource(s) enabled under the Services endpoint configuration (admin/structure/services/list/MY-ENDPOINT/resources) and an attacker must know the endpoint's machine name.

SA-CORE-2019-003 Notice of increased risk and Additional exploit path - PSA-2019-02-22

Date: 
2019-February-23

This Public Service Announcement is a follow-up to SA-CORE-2019-003. This is not an announcement of a new vulnerability. If you have not updated your site as described in SA-CORE-2019-003 you should do that now.

There are public exploits now available for this SA.

Update, February 25: Mass exploits are now being reported in the wild.

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2019-003

Project machine name: 
drupal
Date: 
2019-February-20
CVE IDs: 
CVE-2019-6340

Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

A site is only affected by this if one of the following conditions is met:

Paragraphs - Critical - Remote Code Execution - SA-CONTRIB-2019-023

Project machine name: 
paragraphs
Date: 
2019-February-20

This resolves issues described in SA-CORE-2019-003 for this module. Not all configurations are affected. See SA-CORE-2019-003 for details.

Pages

Subscribe with RSS Subscribe to Security advisories