Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Cloud - Critical - CSRF - SA-CONTRIB-2017-086

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Cloud - Critical - CSRF - SA-CONTRIB-2017-086


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Cloud - Critical - CSRF - SA-CONTRIB-2017-086
  • Date: Wed, 29 Nov 2017 18:47:34 +0000 (UTC)
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2017-086

Project: Cloud [1]
Version: 7.x-1.x-dev
Date: 2017-November-29
Security risk: *Critical* 18∕25
AC:None/A:User/CI:Some/II:All/E:Theoretical/TD:All [2]
Vulnerability: CSRF

Description: 
This module enables sites to manage public clouds like Amazon EC2 and also
private clouds like OpenStack.

The module doesn't sufficiently protect the deletion of audit reports,
thereby exposing a cross-site request vulnerability which can be exploited by
unprivileged users to trick an administrator into unwanted deletion of audit
reports.

This vulnerability is mitigated by the fact that the victim must have a role
with the permission "access audit report".

Solution: 
Install the latest version:

* If you use the Cloud module for Drupal 7, upgrade to Cloud 7.x-1.7 [3]

Reported By: 
* Tatar Balazs Janos [4]

Fixed By: 
* Tatar Balazs Janos [5]
* Yas Naoi [6] the module maintainer

Coordinated By: 
* Tatar Balazs Janos [7]


[1] https://www.drupal.org/project/cloud
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/cloud/releases/7.x-1.7
[4] https://www.drupal.org/u/tatarbj
[5] https://www.drupal.org/u/tatarbj
[6] https://www.drupal.org/u/yas
[7] https://www.drupal.org/u/tatarbj

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] Cloud - Critical - CSRF - SA-CONTRIB-2017-086, security-news, 29.11.2017

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang