Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecurityNotifies] [Security-news] PSA-2010-002 - Views - Administer views permission

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecurityNotifies] [Security-news] PSA-2010-002 - Views - Administer views permission


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecurityNotifies] [Security-news] PSA-2010-002 - Views - Administer views permission
  • Date: Wed, 16 Jun 2010 22:33:06 +0000 (UTC)
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>

* Advisory ID: PSA-2010-002
* Project: Views (third-party module)
* Versions: 5.x, 6.x
* Date: 2010-June-16
* Security risk: Not critical

-------- DESCRIPTION
---------------------------------------------------------

This is a public service announcement regarding the "administer views"
permission provided by the Views module. The Views module provides a flexible
method for Drupal site designers to control how lists and tables of content
are presented. The module grants considerable power to users with "administer
views" permission, with much of a site's behaviour being configurable via the
views administration pages. The permission "administer views" is therefore
comparable in scope to the "administer site configuration" permission. Only
grant this permission to trusted site administrators.
-------- VERSIONS AFFECTED
---------------------------------------------------

* Views module for Drupal 5.x
* Views module for Drupal 6.x

Drupal core is not affected. If you do not use the contributed Views module,
there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------

Only grant trusted site administrators the "administer views" permission.
-------- CONTACT
-------------------------------------------------------------

The security team for Drupal can be reached at security at drupal.org or via
the form at http://drupal.org/contact.

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
http://lists.drupal.org/mailman/listinfo/security-news



  • [IT-SecurityNotifies] [Security-news] PSA-2010-002 - Views - Administer views permission, security-news, 17.06.2010

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang