Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Entity Reference Tab / Accordion Formatter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-008

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Entity Reference Tab / Accordion Formatter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-008


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Entity Reference Tab / Accordion Formatter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-008
  • Date: Wed, 7 Feb 2018 18:59:56 +0000 (UTC)
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2018-008

Project: Entity Reference Tab / Accordion Formatter [1]
Date: 2018-February-07
Security risk: *Moderately critical* 14∕25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross Site Scripting

Description: 
This module enables you to show referenced entities in tabs.

The module doesn't sufficiently sanitize the body fields of the referenced
entities when it prints them to the tabs.

This vulnerability is mitigated by the fact that an attacker must have a role
with the permission create/edit content of the content type that is
referenced.

Solution: 
Install the latest version:

* If you use the Entity Reference Tab / Accordion Formatter module for
Drupal 8.x, upgrade to 8.x-1.3 [3]

Reported By: 
* Tatar Balazs Janos [4] Provisional Security Team member

Fixed By: 
* Tatar Balazs Janos [5] Provisional Security Team member
* Rakesh James [6] the module maintainer

Coordinated By: 
* Tatar Balazs Janos [7] Provisional Security Team member


[1] https://www.drupal.org/project/entity_ref_tab_formatter
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/entity_ref_tab_formatter/releases/8.x-1.3
[4] https://www.drupal.org/u/tatarbj
[5] https://www.drupal.org/u/tatarbj
[6] https://www.drupal.org/user/1177822
[7] https://www.drupal.org/u/tatarbj

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] Entity Reference Tab / Accordion Formatter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2018-008, security-news, 07.02.2018

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang