it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Entity Reference - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-067
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Entity Reference - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-067
- Date: Wed, 16 Aug 2017 18:02:35 +0000 (UTC)
- List-archive: <http://lists.drupal.org/pipermail/security-news/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/node/2902596
* Advisory ID: DRUPAL-SA-CONTRIB-2017-067
* Project: Entity reference [1] (third-party module)
* Version: 7.x
* Date: 2017-August-16
* Security risk: 12/25 ( Moderately Critical)
AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Default [2]
* Vulnerability: Access bypass
-------- DESCRIPTION
---------------------------------------------------------
The entity reference module provides a field type that can reference
arbitrary entities.
In a vulnerable configuration, an attacker could determine the titles of
nodes they do not have access to.
This is mitigated as only entity reference fields using the "simple" entity
selector are vulnerable, and the attack is not possible if any access control
(i.e. node access) is in place (the attacker's role is missing only the
"access content" permission to be able to view the content.)
-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------
* /A CVE identifier [3] will be requested, and added upon issuance, in
accordance with Drupal Security Team processes./
-------- VERSIONS AFFECTED
---------------------------------------------------
* entityreference 7.x-1.x versions prior to 7.x-1.5.
Drupal core is not affected. If you do not use the contributed Entity
reference [4] module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
Install the latest version:
* If you use the entityreference module for Drupal 7.x, upgrade to
entityreference 7.x-1.5 [5]
Also see the Entity reference [6] project page.
-------- REPORTED BY
---------------------------------------------------------
* Greg Knaddison [7] of the Drupal Security Team
* Aaron Ott [8]
-------- FIXED BY
------------------------------------------------------------
* David Pascoe-Deslauriers [9] the module maintainer
-------- COORDINATED BY
------------------------------------------------------
* Pere Orga [10] of the Drupal Security Team
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [11].
Learn more about the Drupal Security team and their policies [12], writing
secure code for Drupal [13], and securing your site [14].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [15]
[1] https://www.drupal.org/project/entityreference
[2] https://www.drupal.org/security-team/risk-levels
[3] http://cve.mitre.org/
[4] https://www.drupal.org/project/entityreference
[5] https://www.drupal.org/node/2902583
[6] https://www.drupal.org/project/entityreference
[7] https://www.drupal.org/u/greggles
[8] https://www.drupal.org/user/154069
[9] https://www.drupal.org/u/spotzero
[10] https://www.drupal.org/user/2301194
[11] https://www.drupal.org/contact
[12] https://www.drupal.org/security-team
[13] https://www.drupal.org/writing-secure-code
[14] https://www.drupal.org/security/secure-configuration
[15] https://twitter.com/drupalsecurity
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecNots] [Security-news] Entity Reference - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-067, security-news, 16.08.2017
Archiv bereitgestellt durch MHonArc 2.6.19.