bootstrap_carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2017-088

Project machine name: 
bootstrap_carousel
Date: 
2017-November-29

This module provides a way to make carousels, based on bootstrap-carousel.js.

The module doesn't sufficiently handle output of img HTML tag's alt property.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Carousel: Create new content" or any similar node module permissions for creating/editing/removing the module-delivered content type.

Services single sign-on client - Critical - Cross-site scripting - SA-CONTRIB-2017-087

Project machine name: 
services_sso_client
Date: 
2017-November-29

This module allows users of a remote Services-enabled Drupal site to sign on to a second site with their credentials.

The module does not sanitize information from the request before displaying it, thereby exposing a cross-site scripting vulnerability.

Cloud - Critical - CSRF - SA-CONTRIB-2017-086

Project machine name: 
cloud
Date: 
2017-November-29

This module enables sites to manage public clouds like Amazon EC2 and also private clouds like OpenStack.

The module doesn't sufficiently protect the deletion of audit reports, thereby exposing a cross-site request vulnerability which can be exploited by unprivileged users to trick an administrator into unwanted deletion of audit reports.

This vulnerability is mitigated by the fact that the victim must have a role with the permission "access audit report".

MoneySuite - Moderately critical - Access bypass - SA-CONTRIB-2017-085

Project machine name: 
moneysuite
Date: 
2017-November-29

MoneySuite provides a set of modules for Drupal sites that rely on the sale of memberships and/or content for revenue.

The modules have an access bypass vulnerability which allows untrusted users (including anonymous users) to view payments made by users within the system. No data can be modified, nor are any credit card numbers displayed.

Domain Integration (Drupal 7) - Moderately critical - Access bypass - SA-CONTRIB-2017-084

Project machine name: 
domain_integration
Date: 
2017-November-29

This module enables you to integrate the Domain module with other popular Drupal modules. The Domain Integration Login Restrict sub-module enables you to restrict access to a domain based on the assigned domains on a user.

The Domain Integration Login Restrict sub-module doesn't sufficiently check these restrictions when using one-time logins.

This vulnerability is mitigated by the fact that an attacker must have an active account on one of the domains.

Custom Permissions - Moderately critical - Access bypass - SA-CONTRIB-2017-083

Project machine name: 
config_perms
Date: 
2017-November-08

Custom Permissions is a lightweight module that allows permissions to be created and managed through an administrative form.

When this module is in use, any user who is able to perform an action which rebuilds some of Drupal's caches can trigger a scenario in which certain pages protected by this module's custom permissions temporarily lose those custom access controls, thereby leading to an access bypass vulnerability.

Permissions by Term - Moderately critical - Access bypass - SA-CONTRIB-2017-082

Project machine name: 
permissions_by_term
Date: 
2017-November-08

The Permissions by Term module extends Drupal by adding functionality for restricting access to single nodes via taxonomy terms.

The module grants access to nodes that are being blocked by other node access modules and that the Permissions by Term module does not intend to control. Additionally, it grants access to unpublished nodes in node listings to users who should not be able to see them. These problems lead to an access bypass vulnerability.

Automated Logout - Moderately critical - Cross Site Scripting - SA-CONTRIB-2017-081

Project machine name: 
autologout
Date: 
2017-November-01

This module provides a site administrator the ability to log users out after a specified time of inactivity. It is highly customizable and includes "site policies" by role to enforce log out.

The module does not sufficiently filter user-supplied text that is stored in the configuration, resulting in a persistent Cross Site Scripting vulnerability (XSS).

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer autologout".

Mosaik - Moderately critical - Cross-site scripting - SA-CONTRIB-2017-080

Project machine name: 
mosaik
Date: 
2017-October-25

The Mosaik module enables you to create pages or complex blocks in Drupal with the logic of a real mosaic and its pieces.

The module doesn't sufficiently sanitize the titles of fieldsets on its administration pages or the titles of blocks that it creates. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer mosaik".

Brilliant Gallery - Highly critical - Multiple Vulnerabilities - SA-CONTRIB-2017-079

Project machine name: 
brilliant_gallery
Date: 
2017-October-25

This module enables you to display any number of galleries based on images located in the files folder.

The module doesn't sufficiently sanitize various database queries which may allow attackers to craft requests resulting in an SQL injection vulnerability. This vulnerability could be exploited even by anonymous users and could potentially allow them to take over the site.

The module doesn't sufficiently confirm a user's intent to save checklist data, which allows for a cross-site request forgery (CSRF) exploit to be executed by unprivileged users.

Yandex.Metrics - Moderately critical - Cross site scripting - SA-CONTRIB-2017-078

Project machine name: 
yandex_metrics
Date: 
2017-October-18

The Yandex.Metrics module allows you to look for key indicators of your site effectiveness.

The module doesn't sufficiently let users know a setting page should not be given to untrusted users.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer Yandex.Metrics settings."

Edited October 19, 2017 to add a note about checking permissions.

netFORUM Authentication - Moderately critical - Access Bypass - SA-CONTRIB-2017-077

Project machine name: 
netforum_authentication
Date: 
2017-October-11

The netFORUM Authentication module implements external authentication for users against netFORUM.

The module does not correctly use flood control making it susceptible to brute force attacks.

Skype Status - Moderately Critical - Cross Site Scripting - DRUPAL-SA-CONTRIB-2017-076

Page Access - Unsupported - SA-CONTRIB-2017-075

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-075
  • Project: Page Access (third-party module)
  • Date: 20-September-2017

Flag clear - Moderately Critical - CSRF - DRUPAL-SA-CONTRIB-2017-074

CAPTCHA - Moderately Critical - Denial of Service - SA-CONTRIB-2017-073

Clientside Validation - Critical - Arbitary PHP Execution - DRUPAL-SA-CONTRIB-2017-072

Update on Views Ajax vulnerability for Drupal 7 Views and Drupal 8 core - PSA-2017-002

Date: 
2017-August-17
  • Advisory ID: DRUPAL-PSA-2017-002
  • Project: Drupal contributed modules
  • Version: 7.x, 8.x
  • Date: 2017-Aug-16

Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-004

Drupal 8.3.7 is a maintenance release which contain fixes for security vulnerabilities.

Views refresh - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-069

Views - Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-068

Session Cache API - Critical - Multiple vulnerabilities - DRUPAL-SA-CONTRIB-2017-065

Better field descriptions - Critical - XSS - SA-CONTRIB-2017-064

Relation - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-063

services_views - Unsupported - SA-CONTRIB-2017-062

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-062
  • Project: services_views (third-party module)
  • Date: 2-Aug-2017

ajax_facets - Unsupported - SA-CONTRIB-2017-061

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-061
  • Project: ajax_facets (third-party module)
  • Date: 2-Aug-2017

baidu_analytics - Unsupported - SA-CONTRIB-2017-060

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-060
  • Project: baidu_analytics (third-party module)
  • Date: 2-Aug-2017

html_title - Unsupported - SA-CONTRIB-2017-059

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-059
  • Project: html_title (third-party module)
  • Date: 2-Aug-2017

Alinks - Moderately Critical -Access bypass - SA-CONTRIB-2017-058

DrupalChat - Critical - Multiple vulnerabilities - SA-CONTRIB-2017-057

OAuth - Critical - Access Bypass - SA-CONTRIB-2017-056

Services - Critical - SQL Injection - SA-CONTRIB-2017-054

Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-003

Drupal 8.3.4 and Drupal 7.56 are maintenance releases which contain fixes for security vulnerabilities.

Search 404 - Moderately Critical - Cross Site Scripting - SA-CONTRIB-2017-053

LDAP - Critical - Data Injection - SA-CONTRIB-2017-052

Site Verify - Moderately Critical - Cross Site Scripting - SA-CONTRIB-2017-051

Custom Landing Page Builder - Unsupported - SA-CONTRIB-2017-050

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-050
  • Project: landing_page (third-party module)
  • Date: 24-May-2017

Bootstrap - Critical - Information Disclosure - SA-CONTRIB-2017-048

DRD Agent - Critical - Multiple vulnerabilities - SA-CONTRIB-2017-047

Drupal Remote Dashboard - Critical - Weak encryption keys - SA-CONTRIB-2017-046

Media - Moderately Critical - Multiple vulnerabilities - SA-CONTRIB-2017-044

shib_auth Moderately Critical - Multiple vulnerabilities - SA-CONTRIB-2017-043

Drupal Core - Critical - Access Bypass - SA-CORE-2017-002

Pages

Subscribe with RSS Subscribe to Security advisories