Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Critical - Cross Site Scripting, Access Bypass - SA-CONTRIB-2021-045

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Critical - Cross Site Scripting, Access Bypass - SA-CONTRIB-2021-045


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Critical - Cross Site Scripting, Access Bypass - SA-CONTRIB-2021-045
  • Date: Wed, 8 Dec 2021 18:28:32 +0000 (UTC)
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2021-045

Project: Webform [1]
Date: 2021-December-08
Security risk: *Critical* 16∕25
AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross Site Scripting, Access Bypass

Description: 
.... Access Bypass:

This module enables you to build forms and surveys in Drupal.

The module doesn't sufficiently check access for administrative features for
webforms attached to nodes using the Webform Node module. This may reveal
submitted data or allow an attacker to modify submitted data.

There is no mitigation for this vulnerability. If you have the Webform Node
module enabled you must update the Webform module.

.... Cross Site Scripting:

The Webform module enables site builders to create forms and surveys.

The Webform module doesn't sufficiently filter HTML when an element's 'Help
title' and an 'Image Select' element's image text contain specially crafted
malicious text.

This vulnerability is mitigated by the fact that an attacker must be able to
create or edit webforms.

Solution: 
Install the latest version:

* If you use the Webform module for Drupal 9.x, upgrade to Webform 6.1.2 [3]
or Webform 6.0.6 [4]
* If you use the Webform module version 8.x-5.x it is affected by this issue
and is unsupported. You should upgrade to Webform 6.

Reported By: 
.... Access Bypass:

* Adam P [5]
* Madelyn Cruz [6]

.... Cross Site Scripting:

* Rohit Tiwari [7]

Fixed By: 
.... Access Bypass:

* Chris McCafferty [8] of the Drupal Security Team
* Greg Knaddison [9] of the Drupal Security Team
* Jacob Rockowitz [10]
* Adam P [11]
* Lee Rowlands [12] of the Drupal Security Team

.... Cross Site Scripting:

* Jacob Rockowitz [13]

Coordinated By: 
* Chris [14] of the Drupal Security Team
* Greg Knaddison [15] of the Drupal Security Team
* Damien McKenna [16] of the Drupal Security Team


[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.1.2
[4] https://www.drupal.org/project/webform/releases/6.0.6
[5] https://www.drupal.org/user/3580554
[6] https://www.drupal.org/user/2523544
[7] https://www.drupal.org/user/3132219
[8] https://www.drupal.org/user/1850070
[9] https://www.drupal.org/user/36762
[10] https://www.drupal.org/user/371407
[11] https://www.drupal.org/user/3580554
[12] https://www.drupal.org/user/395439
[13] https://www.drupal.org/user/371407
[14] https://www.drupal.org/user/1850070
[15] https://www.drupal.org/user/36762
[16] https://www.drupal.org/user/108450

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] Webform - Critical - Cross Site Scripting, Access Bypass - SA-CONTRIB-2021-045, security-news, 08.12.2021

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang