Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] CKEditor Upload Image - Critical - Access bypass - SA-CONTRIB-2018-014

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] CKEditor Upload Image - Critical - Access bypass - SA-CONTRIB-2018-014


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] CKEditor Upload Image - Critical - Access bypass - SA-CONTRIB-2018-014
  • Date: Wed, 21 Feb 2018 19:13:52 +0000 (UTC)
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2018-014

Project: CKEditor Upload Image [1]
Date: 2018-February-21
Security risk: *Critical* 15∕25
AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Description: 
This module enables you to drag and drop or paste images into CKEditor.
The module does not sufficiently verify users permissions, which leads to
anonymous users being able to upload files to the server.

Solution: 
Install the latest version:

* If you use the CKEditor Upload Image module for Drupal 8.x, upgrade to
CKEditor Upload Image 8.x-1.5 [3]

Reported By: 
* Jean-Francois Hovinne [4]

Fixed By: 
* Jean-Francois Hovinne [5]
* Mer [6]
* Greg Knaddison [7] of the Drupal Security Team

Coordinated By: 
* Greg Knaddison [8] of the Drupal Security Team


[1] https://www.drupal.org/project/ckeditor_uploadimage
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ckeditor_uploadimage/releases/8.x-1.5
[4] https://www.drupal.org/user/77723
[5] https://www.drupal.org/user/77723
[6] https://www.drupal.org/user/3513520
[7] https://www.drupal.org/user/36762
[8] https://www.drupal.org/user/36762

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] CKEditor Upload Image - Critical - Access bypass - SA-CONTRIB-2018-014, security-news, 21.02.2018

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang