Bing Autosuggest API - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-058

Project machine name: 
bing_autosuggest_api
Date: 
2018-August-29

This module enables you to use the Bing Autosuggest API.

The module doesn't sufficiently sanitize a value used to populate an API request.

Commerce Core - Moderately critical - Access bypass - SA-CONTRIB-2018-057

Project machine name: 
commerce
Date: 
2018-August-29

This module enables you to build eCommerce websites and applications with Drupal.

The module doesn't sufficiently check access for some of its entity types.

File (Field) Paths - Critical - Remote Code Execution - SA-CONTRIB-2018-056

Project machine name: 
filefield_paths
Date: 
2018-August-15

This module enables you to automatically sort and rename your uploaded files using token based replacement patterns to maintain a nice clean filesystem.

The module doesn't sufficiently sanitize the path while a new file is uploading, allowing a remote attacker to execute arbitrary PHP code.

This vulnerability is mitigated by the fact that an attacker must have access to a form containing a widget processed by this module.

PHP Configuration - Critical - Arbitrary PHP code execution - SA-CONTRIB-2018-055

Project machine name: 
phpconfig
Date: 
2018-August-08

This module enables you to add or overwrite PHP configuration on a drupal website.

The module doesn't sufficiently allow access to set these configurations, leading to arbitrary PHP configuration execution by an attacker.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer phpconfig".

After updating the module, it's important to review the permissions of your website and if 'administer phpconfig' permission is given to a not fully trusted user role, we advise to revoke it.

Drupal Core - 3rd-party libraries -SA-CORE-2018-005

  • Advisory ID: DRUPAL-SA-CORE-2018-005
  • Project: Drupal core
  • Version: 8.x
  • CVE: CVE-2018-14773
  • Date: 2018-August-01

Drupal 8 release on August 1st, 2018 - PSA-2018-07-30

Date: 
2018-July-30

The Drupal Security Team will be coordinating a security release for Drupal 8 this week on Wednesday, August 1, 2018. (We are issuing this PSA in advance because the in the regular security release window schedule, August 1 would not typically be a core security window.)

The Drupal 8 core release will be made between 16:00 – 21:00 UTC (noon – 5:00pm EDT). It is rated as moderately critical and will be an update to a vendor library only.

Select (or other) - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-054

Project machine name: 
select_or_other
Date: 
2018-July-25

This module enables users to select 'other' on certain form elements and a textfield appears for the user to provide a custom value.

The module doesn't sufficiently escape values of a text field the under the scenario when "Select or other" formatter is used.

This vulnerability is mitigated by the fact that an attacker must have access to edit a field that is displayed through the "Select or other" formatter.

XML sitemap - Moderately critical - Information Disclosure - SA-CONTRIB-2018-053

Project machine name: 
xmlsitemap
Date: 
2018-July-18

This module enables you to generate XML sitemaps and it helps search engines to more intelligently crawl a website and keep their results up to date.

The module doesn't sufficiently handle access rights under the scenario of updating contents from cron execution.

Taxonomy Entity Queue - Critical - SQL Injection - SA-CONTRIB-2018-052

Project machine name: 
entityqueue_taxonomy
Date: 
2018-July-18

This module enables you to create an entityqueue based on a taxonomy.

The module did not properly use Drupal's database API when querying the database with user supplied values, allowing an attacker to send a specially crafted request to modify the query or potentially perform additional queries.

This vulnerability is mitigated by the fact that an attacker must have a role with the "administer entity queue taxonomy" permission.

Tapestry - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-051

Project machine name: 
tapestry
Date: 
2018-July-11

This theme provides Drupal users with many advanced features including 20 Different Color Styles, 30 User Regions, Custom Block Theme Templates, Suckerfish Menus, Icon Support, Advanced Page Layout Options, Simple Configuration, Custom Typography...

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.

litejazz - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-050

Project machine name: 
litejazz
Date: 
2018-July-11

This theme features 3 color styles, 12 fully collapsible regions, suckerfish menus, fluid or fixed widths, easy configuration, and more.

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.

NewsFlash - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-049

Project machine name: 
newsflash
Date: 
2018-July-11

This theme features 7 color styles, 12 collapsible regions, suckerfish menus, fluid or fixed widths, and lots more.

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.

Beale Street - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-048

Project machine name: 
bealestreet
Date: 
2018-July-11

This theme features 4 built-in color styles, 18 collapsible regions, Suckerfish menus, flexible widths, adjustable sidebars, configurable font family, and lots more.

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is not exploitable under common site configurations.

EU Cookie Compliance (GDPR Compliance) - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-047

Project machine name: 
eu_cookie_compliance
Date: 
2018-July-11

This module addresses the General Data Protection Regulation (GDPR) that came into effect 25th May 2018, and the EU Directive on Privacy and Electronic Communications from 2012. It provides a banner where you can gather consent from the user to store cookies on their computer and handle their personal information.

This module does not sanitize some inputs leading to XSS. This is mitigated by the attacker having the permission "Administer EU Cookie Compliance."

Commerce Custom Order Status - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-046

Project machine name: 
commerce_custom_order_status
Date: 
2018-July-11

Commerce Custom Order Status provides forms for administrators to add, edit, and delete order statuses from the order settings screen.

The module doesn't sufficiently sanitize the output of the status names.

This vulnerability is mitigated by the fact that an attacker must have a role with the "configure order settings" permission.

Universally Unique IDentifier - Moderately critical - Arbitrary file upload - SA-CONTRIB-2018-045

Project machine name: 
uuid
Date: 
2018-July-04

This module provides an API for adding universally unique identifiers (UUID) to Drupal objects, most notably entities.

The module module has an arbitrary file upload vulnerability when it's used in combination with the services REST server.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to allow to upload to the file create REST endpoint.

TFA Basic plugins - Less critical - Insecure Randomness - SA-CONTRIB-2018-044

Project machine name: 
tfa_basic
Date: 
2018-June-27

The TFA Basic module enables you to use Two Factor Authentication via a variety of plugins including TOTP and one-time codes delivered via email or sms.

The module doesn't use a strong source of randomness, creating weak and predictable one-time login codes that are then delivered using SMS. This weakness does not affect the more common TOTP second factor.

This vulnerability is mitigated by the fact that the site must be configured to use SMS to deliver one-time login codes which is an uncommon configuration.

Mass Password Reset - Less critical - Insecure Randomness - SA-CONTRIB-2018-043

Project machine name: 
mass_pwreset
Date: 
2018-June-27

This module enables you to reset passwords for all users based upon their user role.

The module doesn't use a strong source of randomness, creating weak and predictable passwords.

This vulnerability is mitigated by the fact that the site must be configured to reveal the password to the attacker, which is a common configuration.

Generate Password - Less critical - Insecure Randomness - SA-CONTRIB-2018-042

Project machine name: 
genpass
Date: 
2018-June-27

The Genpass module makes the password field optional (or hidden) on the add new user page (admin & registration). If the password field is not set during registration, the system generates a password.

The module doesn't use a strong source of randomness, creating weak and predictable passwords.

This vulnerability is mitigated by the fact that the site must be configured to reveal the password to the attacker which is a common configuration.

Custom Tokens - Critical - Arbitrary PHP code execution - SA-CONTRIB-2018-041

Project machine name: 
token_custom
Date: 
2018-June-13

The Custom Tokens module enables you to create custom tokens for specific replacements that can improve other modules relying on the token API.

The module doesn't sufficiently identify that its custom permissions are risky and should only be granted to highly trusted roles.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer custom tokens".

Entity Delete - Critical - Multiple Vulnerabilities - SA-CONTRIB-2018-040

Project machine name: 
entity_delete
Date: 
2018-June-06

This module enables you to delete any types of entities in bulk.

The module doesn't sufficiently verify access permissions under its use cases, leading to access bypass. The module also does not protect against Cross Site Request Forgeries on its delete process.

The access bypass vulnerability is mitigated by the fact that an attacker must have a role with the permission "access content". There is no additional mitigation for the Cross Site Request Forgery vulnerability.

AdTego SiteIntel - AdBlocker Detect - Critical - Unsupported - SA-CONTRIB-2018-039

Project machine name: 
adtego_siteintel
Date: 
2018-June-06

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

Mollom - Critical - Unsupported - SA-CONTRIB-2018-038

Project machine name: 
mollom
Date: 
2018-June-06

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported projects critical by default.

Zircon - Critical - Unsupported - SA-CONTRIB-2018-037

Project machine name: 
zircon
Date: 
2018-May-23

Update - 2018-09-26

This maintainer has fixed this security issue. Please install https://www.drupal.org/project/zircon/releases/7.x-1.2 to resolve the issue.


The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

Education - Critical - Unsupported - SA-CONTRIB-2018-036

Project machine name: 
education
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

TB Sirate - Critical - Unsupported - SA-CONTRIB-2018-035

Project machine name: 
tb_sirate
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

Hotel - Critical - Unsupported - SA-CONTRIB-2018-034

Project machine name: 
hotel
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

iShopping - Critical - Unsupported - SA-CONTRIB-2018-033

Project machine name: 
ishopping
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

Corporate Site - Critical - Unsupported - SA-CONTRIB-2018-032

Project machine name: 
corporate_site
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

TB Nucleus - Critical - Unsupported - SA-CONTRIB-2018-031

Project machine name: 
nucleus
Date: 
2018-May-23

Update - 2018-09-26

This maintainer has fixed this security issue. Please install https://www.drupal.org/project/nucleus/releases/7.x-1.6 to fix the security issue


The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

SimpleCrop - Critical - Unsupported - SA-CONTRIB-2018-030

Project machine name: 
simplecrop
Date: 
2018-May-23

Update: 2018-06-01

A new maintainer has stepped forward to maintain this module and has put out a new release.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Baidu Analytics - Critical - Unsupported - SA-CONTRIB-2018-029

Project machine name: 
baidu_analytics
Date: 
2018-May-23

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Protected Pages - Critical - Unsupported - SA-CONTRIB-2018-028

Project machine name: 
protected_pages
Date: 
2018-May-23

Update: 2018-06-03

A new maintainer has stepped forward and this project now has a stable release.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

SVG Formatter - Critical - Cross Site Scripting - SA-CONTRIB-2018-027

Project machine name: 
svg_formatter
Date: 
2018-May-09

This module adds a new formatter for the file fields, which allows any file extension to be uploaded.
The module doesn't sufficiently handle sanitization under the scenario uploaded SVG files.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission create or edit on certain content types that allows SVG files to be uploaded.

Scrollable Content - Critical - Unsupported - SA-CONTRIB-2018-026

Project machine name: 
scrollable_content
Date: 
2018-May-09

Scrollable Content provides a scrolling functionality for your content. Scrollable Content will give you a nice content slider preview of your site's nodes, and provides some display options.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Simple Taxonomy Revision - Critical - Unsupported - SA-CONTRIB-2018-025

Project machine name: 
simple_revision
Date: 
2018-May-09

Simple Taxonomy Revision module enables revisions for taxonomy terms for Drupal 8.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

KCFinder integration - Critical - Unsupported Module - SA-CONTRIB-2018-024

Project machine name: 
kcfinder
Date: 
2018-May-09

KCFinder is a multi-language file / image manager you can use to easily select, insert, upload and arrange images, flash movies, and other kinds of files.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Multi-Step Registration - Critical - Unsupported Module - SA-CONTRIB-2018-023

Project machine name: 
step
Date: 
2018-May-09

With Multi-Step Registration you can create multi-step (wizard) user account registration forms.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

JSON:API - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2018-021

Project machine name: 
jsonapi
Date: 
2018-April-25

This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.

The module doesn't provide CSRF protection when processing authenticated traffic using cookie-based authentication.

This vulnerability is mitigated by the fact that an attacker must be allowed to create or modify entities of a certain type, and a very specific and uncommon CORS configuration that allows all other pre-checks to be skipped.

DRD Agent - Critical - PHP object injection - SA-CONTRIB-2018-022

Project machine name: 
drd_agent
Date: 
2018-April-25

This module enables you to monitor and manage any number of remote Drupal sites and aggregate useful information for administrators in a central dashboard.

The modules (DRD and DRD Agent) encrypt the data which is exchanged between them but in order to do so, they use the PHP serialize/unserialize functions instead of the json_encode/json_decode combination. As the unserialize function is called on unauthenticated content, this introduces a PHP object injection vulnerability.

D7 Media - Critical - Remote Code Execution - SA-CONTRIB-2018-020

Project machine name: 
media
Date: 
2018-April-25

The Media module provides an extensible framework for managing files and multimedia assets, regardless of whether they are hosted on your own site or a third party site.

The module contained a vulnerability similar to SA-CORE-2018-004, leading to a possible remote code execution (RCE) attack.

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

Project machine name: 
drupal
Date: 
2018-April-25
CVE IDs: 
CVE-2018-7602

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

Updated — this vulnerability is being exploited in the wild.

Drupal 7 and 8 core critical release on April 25th, 2018 - PSA-2018-003

Date: 
2018-April-23

There will be a security release of Drupal 7.x, 8.4.x, and 8.5.x on April 25th, 2018 between 16:00 - 18:00 UTC. This PSA is to notify that the Drupal core release is outside of the regular schedule of security releases. For all security updates, the Drupal Security Team urges you to reserve time for core updates at that time because there is some risk that exploits might be developed within hours or days. Security release announcements will appear on the Drupal.org security advisory page.

Display Suite - Critical - Cross site scripting (XSS) - SA-CONTRIB-2018-019

Project machine name: 
ds
Date: 
2018-April-18

Display Suite allows you to take full control over how your content is displayed using a drag and drop interface.

The module doesn't sufficiently validate view modes provided dynamically via URLs leading to a reflected cross site scripting (XSS) attack.

This vulnerability is mitigated only by the fact that most modern browsers protect against reflected XSS via the url.

Menu Import and Export - Critical - Access bypass - SA-CONTRIB-2018-018

Project machine name: 
menu_export
Date: 
2018-April-18

This module helps in exporting and importing Menu Items via the administrative interface.

The module does not properly restrict access to administrative pages, allowing anonymous users to export and import menu links.

There is no mitigation for this vulnerability.

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2018-003

Project machine name: 
drupal
Date: 
2018-April-18
CVE IDs: 
CVE-2018-9861

CKEditor, a third-party JavaScript library included in Drupal core, has fixed a cross-site scripting (XSS) vulnerability. The vulnerability stemmed from the fact that it was possible to execute XSS inside CKEditor when using the image2 plugin (which Drupal 8 core also uses).

We would like to thank the CKEditor team for patching the vulnerability and coordinating the fix and release process, and matching the Drupal core security window.

Drupal Core - Highly Critical - Public Service announcement - PSA-2018-002

Date: 
2018-April-13

Description

This Public Service Announcement is a follow-up to SA-CORE-2018-002 - Drupal core - RCE. This is not an announcement of a new vulnerability. If you have not updated your site as described in SA-CORE-2018-002 you should assume your site has been targeted and follow directions for remediation as described below.

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002

Project machine name: 
drupal
Date: 
2018-March-28
CVE IDs: 
CVE-2018-7600

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.

The security team has written an FAQ about this issue.

Edited 2020, February 13 to fix links to patch files.

Drupal 7 and 8 core highly critical release on March 28th, 2018 - PSA-2018-001

Date: 
2018-March-21
  • Advisory ID: DRUPAL-PSA-2018-001
  • Project: Drupal Core
  • Version: 7.x, 8.x
  • Date: 2018-March-21

Exif - Critical - Access bypass - SA-CONTRIB-2018-017

Project machine name: 
exif
Date: 
2018-March-21

This module enables you to retrieve image metadata and use them in fields or title.

The module doesn't sufficiently restrict access to module setting pages thereby causing an access bypass vulnerability.

This vulnerability is mitigated by the fact that an attacker must have permission to create entities of certain content entity types.

Pages

Subscribe with RSS Subscribe to Security advisories