Hotel - Critical - Unsupported - SA-CONTRIB-2018-034

Project machine name: 
hotel
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

iShopping - Critical - Unsupported - SA-CONTRIB-2018-033

Project machine name: 
ishopping
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

Corporate Site - Critical - Unsupported - SA-CONTRIB-2018-032

Project machine name: 
corporate_site
Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

TB Nucleus - Critical - Unsupported - SA-CONTRIB-2018-031

Project machine name: 
nucleus
Date: 
2018-May-23

Update - 2018-09-26

This maintainer has fixed this security issue. Please install https://www.drupal.org/project/nucleus/releases/7.x-1.6 to fix the security issue


The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

SimpleCrop - Critical - Unsupported - SA-CONTRIB-2018-030

Project machine name: 
simplecrop
Date: 
2018-May-23

Update: 2018-06-01

A new maintainer has stepped forward to maintain this module and has put out a new release.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Baidu Analytics - Critical - Unsupported - SA-CONTRIB-2018-029

Project machine name: 
baidu_analytics
Date: 
2018-May-23

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Protected Pages - Critical - Unsupported - SA-CONTRIB-2018-028

Project machine name: 
protected_pages
Date: 
2018-May-23

Update: 2018-06-03

A new maintainer has stepped forward and this project now has a stable release.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

SVG Formatter - Critical - Cross Site Scripting - SA-CONTRIB-2018-027

Project machine name: 
svg_formatter
Date: 
2018-May-09

This module adds a new formatter for the file fields, which allows any file extension to be uploaded.
The module doesn't sufficiently handle sanitization under the scenario uploaded SVG files.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission create or edit on certain content types that allows SVG files to be uploaded.

Scrollable Content - Critical - Unsupported - SA-CONTRIB-2018-026

Project machine name: 
scrollable_content
Date: 
2018-May-09

Scrollable Content provides a scrolling functionality for your content. Scrollable Content will give you a nice content slider preview of your site's nodes, and provides some display options.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Simple Taxonomy Revision - Critical - Unsupported - SA-CONTRIB-2018-025

Project machine name: 
simple_revision
Date: 
2018-May-09

Simple Taxonomy Revision module enables revisions for taxonomy terms for Drupal 8.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

KCFinder integration - Critical - Unsupported Module - SA-CONTRIB-2018-024

Project machine name: 
kcfinder
Date: 
2018-May-09

KCFinder is a multi-language file / image manager you can use to easily select, insert, upload and arrange images, flash movies, and other kinds of files.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

Multi-Step Registration - Critical - Unsupported Module - SA-CONTRIB-2018-023

Project machine name: 
step
Date: 
2018-May-09

With Multi-Step Registration you can create multi-step (wizard) user account registration forms.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported modules critical by default.

JSON:API - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2018-021

Project machine name: 
jsonapi
Date: 
2018-April-25

This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.

The module doesn't provide CSRF protection when processing authenticated traffic using cookie-based authentication.

This vulnerability is mitigated by the fact that an attacker must be allowed to create or modify entities of a certain type, and a very specific and uncommon CORS configuration that allows all other pre-checks to be skipped.

DRD Agent - Critical - PHP object injection - SA-CONTRIB-2018-022

Project machine name: 
drd_agent
Date: 
2018-April-25

This module enables you to monitor and manage any number of remote Drupal sites and aggregate useful information for administrators in a central dashboard.

The modules (DRD and DRD Agent) encrypt the data which is exchanged between them but in order to do so, they use the PHP serialize/unserialize functions instead of the json_encode/json_decode combination. As the unserialize function is called on unauthenticated content, this introduces a PHP object injection vulnerability.

D7 Media - Critical - Remote Code Execution - SA-CONTRIB-2018-020

Project machine name: 
media
Date: 
2018-April-25

The Media module provides an extensible framework for managing files and multimedia assets, regardless of whether they are hosted on your own site or a third party site.

The module contained a vulnerability similar to SA-CORE-2018-004, leading to a possible remote code execution (RCE) attack.

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

Project machine name: 
drupal
Date: 
2018-April-25
CVE IDs: 
CVE-2018-7602

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

Updated — this vulnerability is being exploited in the wild.

Drupal 7 and 8 core critical release on April 25th, 2018 - PSA-2018-003

Date: 
2018-April-23

There will be a security release of Drupal 7.x, 8.4.x, and 8.5.x on April 25th, 2018 between 16:00 - 18:00 UTC. This PSA is to notify that the Drupal core release is outside of the regular schedule of security releases. For all security updates, the Drupal Security Team urges you to reserve time for core updates at that time because there is some risk that exploits might be developed within hours or days. Security release announcements will appear on the Drupal.org security advisory page.

Display Suite - Critical - Cross site scripting (XSS) - SA-CONTRIB-2018-019

Project machine name: 
ds
Date: 
2018-April-18

Display Suite allows you to take full control over how your content is displayed using a drag and drop interface.

The module doesn't sufficiently validate view modes provided dynamically via URLs leading to a reflected cross site scripting (XSS) attack.

This vulnerability is mitigated only by the fact that most modern browsers protect against reflected XSS via the url.

Menu Import and Export - Critical - Access bypass - SA-CONTRIB-2018-018

Project machine name: 
menu_export
Date: 
2018-April-18

This module helps in exporting and importing Menu Items via the administrative interface.

The module does not properly restrict access to administrative pages, allowing anonymous users to export and import menu links.

There is no mitigation for this vulnerability.

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2018-003

Project machine name: 
drupal
Date: 
2018-April-18
CVE IDs: 
CVE-2018-9861

CKEditor, a third-party JavaScript library included in Drupal core, has fixed a cross-site scripting (XSS) vulnerability. The vulnerability stemmed from the fact that it was possible to execute XSS inside CKEditor when using the image2 plugin (which Drupal 8 core also uses).

We would like to thank the CKEditor team for patching the vulnerability and coordinating the fix and release process, and matching the Drupal core security window.

Drupal Core - Highly Critical - Public Service announcement - PSA-2018-002

Date: 
2018-April-13

Description

This Public Service Announcement is a follow-up to SA-CORE-2018-002 - Drupal core - RCE. This is not an announcement of a new vulnerability. If you have not updated your site as described in SA-CORE-2018-002 you should assume your site has been targeted and follow directions for remediation as described below.

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002

Project machine name: 
drupal
Date: 
2018-March-28
CVE IDs: 
CVE-2018-7600

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.

The security team has written an FAQ about this issue.

Edited 2020, February 13 to fix links to patch files.

Drupal 7 and 8 core highly critical release on March 28th, 2018 - PSA-2018-001

Date: 
2018-March-21
  • Advisory ID: DRUPAL-PSA-2018-001
  • Project: Drupal Core
  • Version: 7.x, 8.x
  • Date: 2018-March-21

Exif - Critical - Access bypass - SA-CONTRIB-2018-017

Project machine name: 
exif
Date: 
2018-March-21

This module enables you to retrieve image metadata and use them in fields or title.

The module doesn't sufficiently restrict access to module setting pages thereby causing an access bypass vulnerability.

This vulnerability is mitigated by the fact that an attacker must have permission to create entities of certain content entity types.

JSON:API - Moderately critical - Access Bypass - SA-CONTRIB-2018-016

Project machine name: 
jsonapi
Date: 
2018-March-21

This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.

The module doesn't sufficiently check access when viewing related resources or relationships, thereby causing an access bypass vulnerability.

This vulnerability is mitigated by the fact that an attacker must be allowed to view the related data, otherwise all they can glean is an entity type UUID and a UUID, which are meaningless by themselves.

JSON:API - Moderately critical - Multiple Vulnerabilities - SA-CONTRIB-2018-015

Project machine name: 
jsonapi
Date: 
2018-February-21

This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.

  • The module doesn't sufficiently associate cacheability metadata in certain situations thereby causing an access bypass vulnerability.

    This vulnerability is mitigated by the fact that an attacker cannot trigger an exploitable situation themselves.

CKEditor Upload Image - Critical - Access bypass - SA-CONTRIB-2018-014

Project machine name: 
ckeditor_uploadimage
Date: 
2018-February-21

This module enables you to drag and drop or paste images into CKEditor.
The module does not sufficiently verify users permissions, which leads to anonymous users being able to upload files to the server.

Drupal core - Critical - Multiple Vulnerabilities - SA-CORE-2018-001

Project machine name: 
drupal
Date: 
2018-February-21

This security advisory fixes multiple vulnerabilities in both Drupal 7 and Drupal 8. See below for a list.

Comment reply form allows access to restricted content - Critical - Drupal 8 - CVE-2017-6926

Users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content.

This vulnerability is mitigated by the fact that the comment system must be enabled and the attacker must have permission to post comments.

Entity API - Moderately critical - Information Disclosure - SA-CONTRIB-2018-013

Project machine name: 
entity
Date: 
2018-February-14

The Entity API module extends the entity API of Drupal core in order to provide a unified way to deal with entities and their properties.

The module prints debugging information to the HTML output in certain error conditions thereby causing an information disclosure vulnerability.

This vulnerability is mitigated by the fact that an attacker needs to be able to trigger the error condition in a way that protected data is exposed.

Entity Backup - Critical - Module Unsupported - SA-CONTRIB-2018-012

Project machine name: 
entity_backup
Date: 
2018-February-14

The main purpose of the Entity Backup module is to keep a backup of deleted Drupal core entities and perform recovery of them.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466

Dynamic Banner - Less critical - Cross site scripting - SA-CONTRIB-2018-011

Project machine name: 
dynamic_banner
Date: 
2018-February-14

This module enables a site to display different banners (via blocks) on different pages depending upon specific criteria.

The module doesn't sufficiently filter output of banner data.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer dynamic_banner".

Custom Permissions - Moderately critical - Access bypass - SA-CONTRIB-2018-010

Project machine name: 
config_perms
Date: 
2018-February-14

This module enables the user to set custom permissions per path.

The module doesn't perform sufficient checks on paths with dynamic arguments (like "node/1" or "user/2"), thereby allowing the site administrator to save custom permissions for paths that won't be protected. This could lead to an access bypass vulnerability if the site is relying on the Custom Permissions module to protect those paths.

This vulnerability is mitigated by the fact that it only occurs on sites which attempted to use the Custom Permissions module to protect dynamic paths.

VChess - Critical - Module Unsupported - SA-CONTRIB-2018-009

Project machine name: 
vchess
Date: 
2018-February-14

The Drupal VChess module allows users to play a chess game.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466

Entity Reference Tab / Accordion Formatter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-008

Project machine name: 
entity_ref_tab_formatter
Date: 
2018-February-07

This module enables you to show referenced entities in tabs.

The module doesn't sufficiently sanitize the body fields of the referenced entities when it prints them to the tabs.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission create/edit content of the content type that is referenced.

FileField Sources - Moderately critical - Access Bypass - SA-CONTRIB-2018-007

Project machine name: 
filefield_sources
Date: 
2018-February-07

This module enables you to upload files to fields via several sources.

The module doesn't sufficiently handle access control under the scenario of the autocomplete path of reference sources.

Taxonomy Term Reference Tree Widget - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-006

Project machine name: 
term_reference_tree
Date: 
2018-January-31

This module provides an expandable tree widget for the Taxonomy Term Reference field in Drupal 7.

The module doesn't sufficiently sanitize the output of its own defined field formatter.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission that allows to edit terms of a taxonomy where the module handles its output.

Sagepay - Critical - Access Bypass - SA-CONTRIB-2018-005

Project machine name: 
sagepay_payment
Date: 
2018-January-31

This module integrates the Sagepay payment service.

Some of the URLs used while processing the payment are not sufficiently secured. This might allow attackers to resume a previously failed payment attempt or to view content that should only be shown after a succesful payment. This affects all payments in a Drupal installation with this module enabled (including payments made using other payment methods).

Backup and Migrate - Critical - Arbitrary PHP code execution - SA-CONTRIB-2018-004

Project machine name: 
backup_migrate
Date: 
2018-January-24

This module enables you to create manual and scheduled backups of a site, and restore the site from backup.

The module doesn't sufficiently identify that its custom permissions are risky and should only be granted to highly trusted roles.

Sites using this module should review the permissions page to verify only trusted users are granted permissions defined by the module.

Bible - Critical - Multiple Vulnerabilities - SA-CONTRIB-2018-003

Project machine name: 
bible
Date: 
2018-January-17

This module enables you to display a Bible on your website. Users can associate notes with a Bible version.

This module has a vulnerability that would allow an attacker to wipe out, update or read notes from other users with a carefully crafted title.

A user must have the "Access Bible content" privilege, which is most likely the default if you have enabled this module.

Node View Permissions - Moderately critical - Access Bypass - SA-CONTRIB-2018-002

Project machine name: 
node_view_permissions
Date: 
2018-January-10

The Node view permissions module enables the "View own content" and "View any content" permissions for each content type on the permissions page.

This module has a vulnerability that allows users with these permissions to view unpublished content that they are not otherwise authorized to view.

This issue was fixed by the maintainer outside of the normal security team protocols. Some issues were patched in 2014 for the 7.x version of this module. The 8.x release was updated within the last 6 months. Both are now flagged as security updates.

Stacks - Critical - Arbitrary PHP code execution - SA-CONTRIB-2018-001

Project machine name: 
stacks
Date: 
2018-January-10

This module enables content editors to create complex pages and layouts on the fly without the help from a developer, using reusable widgets.

The module does not sufficiently filter values posted to its AJAX endpoint, which leads to the instantiation of an arbitrary PHP class.

This vulnerability is mitigated by the fact that only sites with the Stacks - Content Feed submodule enabled are affected.

me aliases - Highly critical - Arbitrary code execution - SA-CONTRIB-2017-097

Project machine name: 
me
Date: 
2017-December-20

'me' module provides shortcut paths to current user's pages, eg user/me, blog/me, user/me/edit, tracker/me etc.

The way 'me' module handles URL arguments allows an attacker to execute arbitrary code strings.

Directory based organisational layer - Critical - Unsupported - SA-CONTRIB-2017-096

Project machine name: 
odir
Date: 
2017-December-20

This module adds a new organizational layer to Drupal, making it easy for managing large numbers of files and nodes.

The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. The security team takes action in cases like this without regard to the severity of the security issue in question. If you would like to maintain this module, please read: https://www.drupal.org/node/251466

ComScore direct tag - Less critical - Cross site scripting - SA-CONTRIB-2017-095

Project machine name: 
comscore_direct
Date: 
2017-December-20

This module enables you to use the comScore Direct analytics system on a site.

The module doesn't sufficiently sanitize one of the configuration variables prior to rendering it.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer comScore direct".

Link Click Count - Critical - Unsupported - SA-CONTRIB-2017-094

Project machine name: 
link_click_count
Date: 
2017-December-20

The Link Click Count module helps you to monitor the traffic to your website by creating link fields. These link fields can be individual links or internal/external links that can be added to the content type.

Panopoly Core - Moderately critical - Cross Site Scripting - SA-CONTRIB-2017-093

Project machine name: 
panopoly_core
Date: 
2017-December-13

This module provides common functionality used by other modules in the Panopoly distribution and child distributions, like, Open Atrium.

The module doesn't sufficiently filter node titles used in breadcrumbs when the "Append Page Title to Site Breadcrumb" setting is enabled.

This vulnerability is mitigated by the fact that an attacker must have a role with the ability to create content.

Node feedback - Moderately critical - Access Bypass - SA-CONTRIB-2017-092

Project machine name: 
node_feedback
Date: 
2017-December-06

This module enables you to set nodes to send feedbacks by personal/site wide contact forms.
The module doesn't sufficiently handle the access to nodes whose titles will be shown on contact forms.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Use the site-wide contact form" or "Use users' personal contact forms" which is often assigned to untrusted user roles such as anonymous.

Configuration Update Manager - Moderately critical - Cross Site Request Forgery (CSRF) - SA-CONTRIB-2017-091

Project machine name: 
config_update
Date: 
2017-December-06

The Configuration Update Reports sub-module in the Configuration Update module project enables you to run reports to see what configuration on your site differs from the configuration distributed by a module, theme, or installation profile, and to revert, delete, or import configuration.

This module doesn't sufficiently protect the Import operation, thereby exposing a Cross Site Request Forgery (CSRF) vulnerability which can be exploited by unprivileged users to trick an administrator into unwanted import of configuration.

Feedback Collect - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-090

Project machine name: 
feedback_collect
Date: 
2017-December-06

This module enables you to add feedback forms and gather end user feedback, bug reports or any kind of suggestions. 

The module doesn't sufficiently filter output of its own fields under the scenario of creating or editing feedback-collect content types.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "create feedback-collect content" or its related editing permissions.

Mailhandler - Critical - Remote Code Execution - SA-CONTRIB-2017-089

Project machine name: 
mailhandler
Date: 
2017-December-06

The Mailhandler module enables you to create nodes by email.

The Mailhandler module does not validate file attachments. By sending a correctly crafted e-mail to a mailhandler mailbox an attacker can execute arbitrary code.

The vulnerability applies to any active mailhandler mailbox, whether or not attachments are mapped to a field.

Mitigating factors:

Pages

Subscribe with RSS Subscribe to Security advisories