Open Social - Critical - Authentication Bypass - SA-CONTRIB-2021-011

Date: 
2021-June-02

Open Social is a Drupal distribution for online communities.

The included social_magic_login module doesn't sufficiently validate magic login URLs for user accounts. The lack of validation makes it possible for an adversary to forge valid login URLs and login to such an account.

This vulnerability is mitigated by the fact the module social_magic_login needs to be enabled.

Open Social - Moderately critical - SQL Injection - SA-CONTRIB-2021-010

Date: 
2021-June-02

This Open Social distribution provides a turn-key system for building customized social networks.

The module doesn't sufficiently process data in certain circumstances.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access mentions".

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-003

Date: 
2021-May-26
CVE IDs: 
CVE-2021-33829

Update: 2021-06-11: Added CVE-2021-33829 identifier

Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to an XSS attack. CKEditor 4.16.1 and later include the fix.

Update: 2021-06-11: More details are available on CKEditor's blog.

Off Cycle Drupal Core Security Release - PSA-2021-05-25

Date: 
2021-May-25

Update: After some delays, the new estimate for this release is 20:00UTC on May 26th, 2021. Apologies for the inconvenience.

Chaos Tool Suite (ctools) - Moderately critical - Information disclosure - SA-CONTRIB-2021-009

Date: 
2021-May-12

Chaos tool suite (ctools) module provides a number of APIs and extensions for Drupal, it's 8.x-3.x branch is a start from scratch to evaluate the features of ctools that didn't make it into Drupal Core 8.0.x and port them.

The module doesn't sufficiently handle access control on its EntityView plugin.

This vulnerability is mitigated by the fact that successful exploitation requires special conditions in place such as custom solutions that allow injecting the context by means other than the route.

Facets - Moderately critical - Cross site scripting - SA-CONTRIB-2021-008

Date: 
2021-May-12

This module enables you to add customizable facets on search pages, from core search or searches provided by Search API.

The module doesn't sufficiently filter all output in certain circumstances.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer facets".

Gutenberg - Critical - Access bypass - SA-CONTRIB-2021-007

Date: 
2021-May-12

This module provides a new UI experience for node editing using the Gutenberg Editor library.

The module did not correctly validate access rules in certain situations allowing anonymous users to delete blocks.

Drupal core - Critical - Cross-site scripting - SA-CORE-2021-002

Date: 
2021-April-21
CVE IDs: 
CVE-2020-13672

Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances.

Not all sites and users are affected, but configuration changes to prevent the exploit might be impractical and will vary between sites. Therefore, we recommend all sites update to this release as soon as possible.

Fast Autocomplete - Moderately critical - Access bypass - SA-CONTRIB-2021-005

Date: 
2021-March-17

The Fast Autocomplete module provides fast IMDB-like suggestions below a text input field. Suggestions are stored as JSON files in the public files folder so that they can be provided to the browser relatively fast without the need for Drupal to be bootstrapped.

The module doesn't correctly generate certain hashes when the configuration option "Perform search as anonymous user only" is switched from the default on value to off.

Pages

Subscribe with RSS Subscribe to Security advisories