Expand collapse formatter - Critical - Unsupported - SA-CONTRIB-2019-011

Project machine name: 
expand_collapse_formatter
Date: 
2019-January-23

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

Gridstack field - Critical - Unsupported - SA-CONTRIB-2019-008

Project machine name: 
gridstack_field
Date: 
2019-January-23

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

Panels Breadcrumbs - Moderately critical - Cross site scripting - SA-CONTRIB-2019-007

Project machine name: 
panels_breadcrumbs
Date: 
2019-January-23

Panels Breadcrumbs allows you to set your breadcrumbs directly from Panels configuration.

This module doesn't properly sanitize custom breadcrumb configuration in all cases, leading to an XSS vulnerability.

This vulnerability is mitigated by the fact that an attacker must have permission to edit breadcrumb configuration, or the value of a token used in breadcrumb configuration.

Image Annotator [Annotorious] - Critical - Unsupported - SA-CONTRIB-2019-006

Project machine name: 
img_annotator
Date: 
2019-January-23

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

Webform Table Element - Critical - Unsupported - SA-CONTRIB-2019-005

Project machine name: 
webform_table_element
Date: 
2019-January-23

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

Preview Link - Moderately critical - Access bypass - SA-CONTRIB-2019-004

Project machine name: 
preview_link
Date: 
2019-January-23

The Preview Link module enables you to generate preview links so anonymous users can access unpublished revisions of content.
The last release of the module introduced an access bypass allowing users to present invalid tokens but still access unpublished content.

Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2019-002

Project machine name: 
drupal
Date: 
2019-January-16
CVE IDs: 
CVE-2019-6339

A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI.

Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability.

This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

Drupal core - Critical - Third Party Libraries - SA-CORE-2019-001

Project machine name: 
drupal
Date: 
2019-January-16
CVE IDs: 
CVE-2019-6338

Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details.

Aegir HTTPS - Moderately critical - Access bypass - SA-CONTRIB-2019-003

Project machine name: 
hosting_https
Date: 
2019-January-09

Aegir is a Web hosting control panel program that provides a Drupal-based graphical interface designed to simplify deploying, managing and upgrading an entire network of Drupal, Wordpress and CiviCRM Web sites. The Hosting HTTPS module is a commonly used piece of the Aegir platform.

This module doesn't sufficiently shield multi-site installations.

This vulnerability is mitigated by the fact that the server must be using Apache and must host multiple sites on a common platform. An attacker must have a knowledge about used filenames and the server.

Provision - Moderately critical - Access bypass - SA-CONTRIB-2019-002

Project machine name: 
provision
Date: 
2019-January-09

Aegir is a Web hosting control panel program that provides a Drupal-based graphical interface designed to simplify deploying, managing and upgrading an entire network of Drupal, Wordpress and CiviCRM Web sites. The Provision module is a core piece of the Aegir platform.

This module doesn't sufficiently shield multi-site installations or the PHP source code.

Phone Field - Critical - SQL Injection - SA-CONTRIB-2019-001

Project machine name: 
phonefield
Date: 
2019-January-09

This module provides a phone field for Drupal 7 that supports the HTML5 tel:-schema.

In an API function that is not used by the module, the name for the phone field is not sufficiently sanitised when using it in database queries.

This vulnerability is mitigated by the fact that it affects an unused function. A site is only vulnerable if it has custom code that uses the phonefield_get_entity_id() function and exposes control over the $field parameter to visitors to the site.

JSON:API - Moderately critical - Access bypass - SA-CONTRIB-2018-081

Project machine name: 
jsonapi
Date: 
2018-December-19

This module provides a JSON:API specification-compliant HTTP API for accessing and manipulating Drupal content and configuration entities.

The module doesn't sufficiently check access when responding to certain filtered collection requests, thereby causing an access bypass vulnerability. (This means certain GET requests are vulnerable; no POST, PATCH or DELETE requests are vulnerable.)

E-Sign - Moderately critical - Cross site scripting - SA-CONTRIB-2018-080

Project machine name: 
esign
Date: 
2018-December-19

This module allows for integration of Signature Pad, an electronic-signing
script, into Drupal for both nodes (content), the Field API (FAPI), and Webforms.

The module doesn't sufficiently filter user input when displaying a signature.

The vulnerability is mitigated by the fact that an attacker must have the ability to submit a signature. That permission might be associated with submitting a webform or creating or editing a node depending on site configuration.

Responsive Menus - Moderately critical - Cross site scripting - SA-CONTRIB-2018-079

Project machine name: 
responsive_menus
Date: 
2018-December-05

This module enables you to collapse your sites main menu on mobile, and show a menu toggle button.

The module doesn't sufficiently sanitize configuration settings provided by users which leads to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer responsive menus".

Salesforce Suite - Moderately critical - Access bypass - SA-CONTRIB-2018-078

Project machine name: 
salesforce
Date: 
2018-December-05

This module enables Drupal to synchronize entities with Salesforce records. The module includes a page that does not sufficiently protect access rights, resulting in potential information disclosure.

This vulnerability is mitigated by the fact that only Drupal entity title and IDs, and Salesforce record IDs are exposed. Entity content and metadata are appropriately protected. Disclosure of Salesforce ID does not confer any additional privileges.

Password Policy - Less critical - Denial of Service - SA-CONTRIB-2018-077

Project machine name: 
password_policy
Date: 
2018-December-05

The Password Policy module makes it possible to set constraints on user passwords which disallow certain passwords.

The "digit placement" constraint is vulnerable to Denial of Service attacks if an attacker submits specially crafted passwords which can cause a site to become unresponsive.

This vulnerability is mitigated by the fact that a site must have the "digit placement" constraint enabled.

Date Reminder - Moderately critical - Access bypass - SA-CONTRIB-2018-076

Project machine name: 
datereminder
Date: 
2018-November-28

This module allows registered users to request email reminders to be sent at a specified time before an event.

The module doesn't sufficiently check access to nodes, allowing a user to set a reminder on a node that the user shouldn't be able to access.

This can be mitigated with configuring DateReminder with Reminder Display: "Fieldset within a node" disables the potential exploit.

GatherContent - Moderately critical - Access bypass - SA-CONTRIB-2018-075

Project machine name: 
gathercontent
Date: 
2018-November-28

This module enables you to import and export data from the GatherContent service.

The module didn't properly protect its administrative paths.

Bootstrap - Moderately critical - Cross site scripting - SA-CONTRIB-2018-074

Project machine name: 
bootstrap
Date: 
2018-November-28

This base theme bridges the gap between Drupal and the Bootstrap Framework.

The theme doesn't sufficiently filter valid targets under the scenario of opening modals, popovers, and tooltips.

This vulnerability is mitigated by the fact that an attacker must already have the ability to either:

Paragraphs - Moderately critical - Access Bypass - SA-CONTRIB-2018-073

Project machine name: 
paragraphs
Date: 
2018-October-31

The Paragraphs module allows Drupal Site Builders to make content organization cleaner so that you can give more editing power to end-users.

The module doesn't sufficiently check access to create new paragraph entities which can cause access bypass issues when used in combination with other contributed modules.

Session Limit - Critical - Insecure Session Management - SA-CONTRIB-2018-072

Project machine name: 
session_limit
Date: 
2018-October-31

The session limit module enables a site administrator to set a policy around the number of active sessions users of the site may have. This is typically set to one so that you can only be logged in once with the same user account.

In one configuration of the module, when a user logs in with another session elsewhere already active, the module asks the user which session should be closed before they can proceed with login. The module does not sufficiently tokenise the list of sessions so that the user's session keys can be found through inspection of the form.

Decoupled Router - Critical - Access bypass - SA-CONTRIB-2018-071

Project machine name: 
decoupled_router
Date: 
2018-October-31

This module enables you to resolve the provided Drupal path in order to find the canonical path and information about the resolved entity. This information includes entity type ID, entity ID, entity UUID and entity label.

The module doesn't sufficiently check access before displaying entity labels. This leads to the display of labels on entities that are not be accessible, for example; titles of unpublished content.

Search Autocomplete - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-070

Project machine name: 
search_autocomplete
Date: 
2018-October-17
CVE IDs: 
CVE-2018-7603

This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc..).

The module doesn't sufficiently filter user-entered text among the autocompletion items leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability can be exploited by any user allowed to create one of the autocompletion item, for instance, nodes, users, comments.

Drupal 7.x and 8.x release on Oct 17th, 2018 - PSA-2018-10-17

Date: 
2018-October-17

The Drupal Security team has a core and contrib release window on the 3rd Wednesday of the month. This window normally ends at 5pm Eastern (9PM UTC).

Due to unforeseen circumstances, we are extending the current window we are in by 3 hours until Oct 17th, 2018 at 8pm Eastern (11:59PM UTC).

HTML Mail - Critical - Remote Code Execution - SA-CONTRIB-2018-069

Project machine name: 
htmlmail
Date: 
2018-October-17

The HTML Mail module lets you theme your messages the same way you theme the rest of your website.

When sending email some variables were not being sanitized for shell arguments, which could lead to remote code execution.

This issue is related to the Drupal Core release SA-CORE-2018-006.

Mime Mail - Critical - Remote Code Execution - SA-CONTRIB-2018-068

Project machine name: 
mimemail
Date: 
2018-October-17

The MIME Mail module allows to send MIME-encoded e-mail messages with embedded images and attachments.

The module doesn't sufficiently sanitized some variables for shell arguments when sending email, which could lead to arbitrary remote code execution.

This issue is related to the Drupal Core release SA-CORE-2018-006.

Drupal Core - Multiple Vulnerabilities - SA-CORE-2018-006

  • Advisory ID: DRUPAL-SA-CORE-2018-006
  • Project: Drupal core
  • Version: 7.x, 8.x
  • Date: 2018-October-17

Workbench Moderation - Moderately critical - Access bypass - SA-CONTRIB-2018-067

Project machine name: 
workbench_moderation
Date: 
2018-October-17

The Workbench Moderation module adds arbitrary moderation states to Drupal core's "unpublished" and "published" node states, and affects the behavior of node revisions when nodes are published.

In some conditions, content moderation fails to check a users access to use certain transitions, leading to an access bypass.

This issue is related to the Drupal Core release SA-CORE-2018-006.

NVP field - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-066

Project machine name: 
nvp
Date: 
2018-October-10

NVP field module allows you to create a field type of name/value pairs, with custom
titles and easily editable rendering with customizable HTML/text surrounding the pairs.

The module doesn't sufficiently handle sanitization of its field formatter's output.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission of creating/editing content where the module defined fields are in use.

Search API Solr - Moderately critical - Access bypass - SA-CONTRIB-2018-065

Project machine name: 
search_api_solr
Date: 
2018-October-10

This module provides support for creating searches using the Apache Solr search engine and the Search API Drupal module.

The module doesn't sufficiently take the searched fulltext fields into account when creating a search excerpt. This can, in specific cases, lead to confidential data being leaked as part of the search excerpt.

Lightbox2 - Critical - Cross Site Scripting - SA-CONTRIB-2018-064

Project machine name: 
lightbox2
Date: 
2018-October-10

The Lightbox2 module enables you to overlay images on the current page.

The module did not sanitize some inputs when used in combination with a custom view leading to potential Cross Site Scripting (XSS).

Printer, email and PDF versions - Highly critical - Remote Code Execution - SA-CONTRIB-2018-063

Project machine name: 
print
Date: 
2018-October-03

This module provides printer-friendly versions of content, including send by e-mail and PDF versions.

The module doesn't sufficiently sanitize the arguments passed to the wkhtmltopdf executable, allowing a remote attacker to execute arbitrary shell commands. It also doesn't sufficiently sanitize the HTML content passed to dompdf, allowing a privileged attacker to execute arbitrary PHP code.

Commerce Klarna Checkout - Moderately critical - Access bypass - SA-CONTRIB-2018-062

Project machine name: 
commerce_klarna_checkout
Date: 
2018-September-26

The Commerce Klarna Checkout module enables you to accept payments from the Klarna Checkout payment provider

The module doesn't sufficiently validate the payment callback made by Klarna. An attacker could bypass the payment step.

Taxonomy File Tree - Moderately critical - Access bypass - SA-CONTRIB-2018-061

Project machine name: 
tft
Date: 
2018-September-26

Taxonomy File Tree allows site managers to create file trees.

For files managed as Drupal files, the module does not properly check that a user has access to a file before letting the user download the file.

This vulnerability only affects sites that use private files.

Renderkit - Moderately critical - Access bypass - SA-CONTRIB-2018-060

Project machine name: 
renderkit
Date: 
2018-September-19

This module, typically in combination with cfr:cfrplugin, allows to compose behaviors from granular components. One of such behaviors is to display a list of related entities, for a given source entity and a given entity relation (e.g. an entity reference field).

The components that display related content do not check if the user has access to view the related entities. This way e.g. unpublished nodes may be displayed to anonymous visitors.

Fraction - Less critical - XSS vulnerability - SA-CONTRIB-2018-059

Project machine name: 
fraction
Date: 
2018-September-05

This module enables you to create fields for storing decimal values as two integers (numerator and denominator) for maximum precision.

The module doesn't sufficiently filter XSS strings out of field labels.

This vulnerability is mitigated by the fact that an attacker must have a role with the ability to manage field configuration.

Bing Autosuggest API - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-058

Project machine name: 
bing_autosuggest_api
Date: 
2018-August-29

This module enables you to use the Bing Autosuggest API.

The module doesn't sufficiently sanitize a value used to populate an API request.

Commerce Core - Moderately critical - Access bypass - SA-CONTRIB-2018-057

Project machine name: 
commerce
Date: 
2018-August-29

This module enables you to build eCommerce websites and applications with Drupal.

The module doesn't sufficiently check access for some of its entity types.

File (Field) Paths - Critical - Remote Code Execution - SA-CONTRIB-2018-056

Project machine name: 
filefield_paths
Date: 
2018-August-15

This module enables you to automatically sort and rename your uploaded files using token based replacement patterns to maintain a nice clean filesystem.

The module doesn't sufficiently sanitize the path while a new file is uploading, allowing a remote attacker to execute arbitrary PHP code.

This vulnerability is mitigated by the fact that an attacker must have access to a form containing a widget processed by this module.

PHP Configuration - Critical - Arbitrary PHP code execution - SA-CONTRIB-2018-055

Project machine name: 
phpconfig
Date: 
2018-August-08

This module enables you to add or overwrite PHP configuration on a drupal website.

The module doesn't sufficiently allow access to set these configurations, leading to arbitrary PHP configuration execution by an attacker.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer phpconfig".

After updating the module, it's important to review the permissions of your website and if 'administer phpconfig' permission is given to a not fully trusted user role, we advise to revoke it.

Drupal Core - 3rd-party libraries -SA-CORE-2018-005

  • Advisory ID: DRUPAL-SA-CORE-2018-005
  • Project: Drupal core
  • Version: 8.x
  • CVE: CVE-2018-14773
  • Date: 2018-August-01

Drupal 8 release on August 1st, 2018 - PSA-2018-07-30

Date: 
2018-July-30

The Drupal Security Team will be coordinating a security release for Drupal 8 this week on Wednesday, August 1, 2018. (We are issuing this PSA in advance because the in the regular security release window schedule, August 1 would not typically be a core security window.)

The Drupal 8 core release will be made between 16:00 – 21:00 UTC (noon – 5:00pm EDT). It is rated as moderately critical and will be an update to a vendor library only.

Select (or other) - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-054

Project machine name: 
select_or_other
Date: 
2018-July-25

This module enables users to select 'other' on certain form elements and a textfield appears for the user to provide a custom value.

The module doesn't sufficiently escape values of a text field the under the scenario when "Select or other" formatter is used.

This vulnerability is mitigated by the fact that an attacker must have access to edit a field that is displayed through the "Select or other" formatter.

XML sitemap - Moderately critical - Information Disclosure - SA-CONTRIB-2018-053

Project machine name: 
xmlsitemap
Date: 
2018-July-18

This module enables you to generate XML sitemaps and it helps search engines to more intelligently crawl a website and keep their results up to date.

The module doesn't sufficiently handle access rights under the scenario of updating contents from cron execution.

Taxonomy Entity Queue - Critical - SQL Injection - SA-CONTRIB-2018-052

Project machine name: 
entityqueue_taxonomy
Date: 
2018-July-18

This module enables you to create an entityqueue based on a taxonomy.

The module did not properly use Drupal's database API when querying the database with user supplied values, allowing an attacker to send a specially crafted request to modify the query or potentially perform additional queries.

This vulnerability is mitigated by the fact that an attacker must have a role with the "administer entity queue taxonomy" permission.

Tapestry - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-051

Project machine name: 
tapestry
Date: 
2018-July-11

This theme provides Drupal users with many advanced features including 20 Different Color Styles, 30 User Regions, Custom Block Theme Templates, Suckerfish Menus, Icon Support, Advanced Page Layout Options, Simple Configuration, Custom Typography...

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.

litejazz - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-050

Project machine name: 
litejazz
Date: 
2018-July-11

This theme features 3 color styles, 12 fully collapsible regions, suckerfish menus, fluid or fixed widths, easy configuration, and more.

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.

NewsFlash - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-049

Project machine name: 
newsflash
Date: 
2018-July-11

This theme features 7 color styles, 12 collapsible regions, suckerfish menus, fluid or fixed widths, and lots more.

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.

Beale Street - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-048

Project machine name: 
bealestreet
Date: 
2018-July-11

This theme features 4 built-in color styles, 18 collapsible regions, Suckerfish menus, flexible widths, adjustable sidebars, configurable font family, and lots more.

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is not exploitable under common site configurations.

EU Cookie Compliance (GDPR Compliance) - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-047

Project machine name: 
eu_cookie_compliance
Date: 
2018-July-11

This module addresses the General Data Protection Regulation (GDPR) that came into effect 25th May 2018, and the EU Directive on Privacy and Electronic Communications from 2012. It provides a banner where you can gather consent from the user to store cookies on their computer and handle their personal information.

This module does not sanitize some inputs leading to XSS. This is mitigated by the attacker having the permission "Administer EU Cookie Compliance."

Pages

Subscribe with RSS Subscribe to Security advisories