Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-023 - Workflow - Cross Site Scripting

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-023 - Workflow - Cross Site Scripting


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-023 - Workflow - Cross Site Scripting
  • Date: Wed, 3 Mar 2010 18:54:43 +0000 (UTC)
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>

* Advisory ID: DRUPAL-SA-CONTRIB-2010-023
* Project: Workflow (third-party module)
* Version: 6.x, 5.x
* Date: 2010-March-03
* Security risk: Less Critical
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting

-------- DESCRIPTION
---------------------------------------------------------

When used in combination with the Token module, the Workflow module does not
escape the text entered into the Comment field of the workflow fieldset on
the node form. This allows a user with the permission to change the workflow
state of a node to perform a Cross Site Scripting (XSS [1]) attack if a
workflow has been assigned to that content type and the option to "Show a
comment field in the workflow section of the editing form" or "Show a comment
field in the workflow section of the workflow tab form" is checked in the
workflow settings. Both are checked by default.
-------- VERSIONS AFFECTED
---------------------------------------------------

* Workflow 6.x-1.x prior to 6.x-1.4 [2]
* Workflow 5.x-2.x prior to 5.x-2.6 [3]

Drupal core is not affected. If you do not use the contributed Workflow
module and the contributed Token module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------

Install the latest version:
* If you use Workflow 6.x-1.x, upgrade to Workflow 6.x-1.4 [4]
* If you use Workflow 5.x-2.x, upgrade to Workflow 5.x-2.6 [5]

See also the Workflow project page [6].
-------- REPORTED BY
---------------------------------------------------------

* George Cassie (gcassie [7])

-------- FIXED BY
------------------------------------------------------------

* John VanDyk (jvandyk [8]), module maintainer

-------- CONTACT
-------------------------------------------------------------

The security contact for Drupal can be reached at security at drupal.org or
via the form at http://drupal.org/contact.

[1] http://en.wikipedia.org/wiki/Cross-site_scripting
[2] http://drupal.org/node/731648
[3] http://drupal.org/node/731644
[4] http://drupal.org/node/731648
[5] http://drupal.org/node/731644
[6] http://drupal.org/project/workflow
[7] http://drupal.org/user/80260
[8] http://drupal.org/user/2375

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
http://lists.drupal.org/mailman/listinfo/security-news



  • [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-023 - Workflow - Cross Site Scripting, security-news, 03.03.2010

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang