it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Link Click Count - Critical - Unsupported - SA-CONTRIB-2017-094
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Link Click Count - Critical - Unsupported - SA-CONTRIB-2017-094
- Date: Wed, 20 Dec 2017 19:17:36 +0000 (UTC)
- List-archive: <http://lists.drupal.org/pipermail/security-news/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2017-094
Project: Link Click Count [1]
Date: 2017-December-20
Security risk: *Critical* 18∕25
AC:None/A:None/CI:Some/II:Some/E:Proof/TD:Default [2]
Vulnerability: Unsupported
Description:
The Link Click Count module helps you to monitor the traffic to your website
by creating link fields. These link fields can be individual links or
internal/external links that can be added to the content type.
The security team is marking this module unsupported. There is a known
security issue with the module that has not been fixed by the maintainer. The
security team takes action in cases like this without regard to the severity
of the security issue in question. If you would like to maintain this module,
please read: https://www.drupal.org/node/251466 [3]
All projects that are being marked unsupported are given a score of critical.
Code that is no longer maintained poses a threat to securing sites.
Solution:
If you use the link click count module for Drupal you should uninstall it.
Reported By:
Karthik Kumar D K [4]
Fixed By:
N/A
[1] https://www.drupal.org/project/link_click_count
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/node/251466
[4] https://www.drupal.org/u/heykarthikwithu
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecNots] [Security-news] Link Click Count - Critical - Unsupported - SA-CONTRIB-2017-094, security-news, 20.12.2017
Archiv bereitgestellt durch MHonArc 2.6.19.