it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] SA-CONTRIB-2011-013 - Tagadelic - Cross Site Scripting (XSS)
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] SA-CONTRIB-2011-013 - Tagadelic - Cross Site Scripting (XSS)
- Date: Wed, 16 Mar 2011 19:20:51 +0000 (UTC)
- List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
- List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
* Advisory ID: DRUPAL-SA-CONTRIB-2011-013
* Project: Tagadelic (third-party module)
* Version: 6.x
* Date: 2011-March-16
* Security risk: Moderately Critical (definition of risk levels) [1]
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting
-------- DESCRIPTION
---------------------------------------------------------
Tagadelic module offers various ways to display terms and vocabularies in a
tag cloud on a page or in a block. The module does not sanitize the taxonomy
vocabulary names and descriptions when displayed on listing pages or blocks,
leading to a Cross-Site Scripting (XSS [2]) vulnerability that may lead to a
malicious user gaining full administrative access.
This vulnerability is mitigated by the fact that the user must be able to
create or edit taxonomy vocabularies, normally restricted by the "administer
taxonomy" permission, in order to exploit it.
-------- VERSIONS AFFECTED
---------------------------------------------------
* Tagadelic module 6.x-1.x versions prior to 6.x-1.3
Note: If you do not use the contributed Tagadelic [3] module, there is
nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
Install the latest version:
* If you use the Tagadelic module for Drupal 6.x-1.x upgrade to Tagadelic
6.x-1.3 [4]
See also the Tagadelic project page [5].
-------- REPORTED BY
---------------------------------------------------------
* Greg Knaddison (greggles) [6] of the Drupal Security Team
-------- FIXED BY
------------------------------------------------------------
* Bèr Kessels [7], module maintainer
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
form at http://drupal.org/contact. Learn more about the team and their
policies [8], writing secure code for Drupal [9], and secure configuration
[10] of your site.
[1] http://drupal.org/security-team/risk-levels
[2] http://en.wikipedia.org/wiki/Cross-site_scripting
[3] http://drupal.org/project/tagadelic
[4] http://drupal.org/node/1095016
[5] http://drupal.org/project/tagadelic
[6] http://drupal.org/user/36762
[7] http://drupal.org/user/2663
[8] http://drupal.org/security-team
[9] http://drupal.org/writing-secure-code
[10] http://drupal.org/security/secure-configuration
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
http://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecNots] [Security-news] SA-CONTRIB-2011-013 - Tagadelic - Cross Site Scripting (XSS), security-news, 16.03.2011
Archiv bereitgestellt durch MHonArc 2.6.19.