Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Tarte au Citron - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-064

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Tarte au Citron - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-064


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Tarte au Citron - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-064
  • Date: Wed, 27 Nov 2024 17:44:22 +0000 (UTC)
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=ag+hzBnB; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; dmarc=pass (policy=none) header.from=drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp1.osuosl.org DF42884EDD
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org C0DC06061E
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2024-064

Project: Tarte au Citron [1]
Date: 2024-November-27
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross Site Scripting

Affected versions: <2.0.5
Description: 
This module integrates Tarte au citron JS library with Drupal and prevent
services to be loaded without user consent. Administrators can enable and
configure services which will be managed by Tarte au citron.

When Google Tag Manager (GTM) service is enabled, an attacker can load a GTM
container that can completely change the page or insert malicious JS.

This vulnerability is mitigated by the fact that the attacker must have a
role with the permission "administer tarte au citron".

Solution: 
Install the latest version and confirm only trusted roles have the
"Administer Tarte au citron" permission.

* If you use the Tarte au citron module for Drupal 10.x, upgrade to Tarte au
citron 2.0.5 [3]

Reported By: 
* Pierre Rudloff [4]

Fixed By: 
* Kévin Le lostec [5]

Coordinated By: 
* Greg Knaddison [6] of the Drupal Security Team
* Juraj Nemec [7] of the Drupal Security Team
* cilefen [8] of the Drupal Security Team


[1] https://www.drupal.org/project/tarte_au_citron
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/tarte_au_citron/releases/2.0.5
[4] https://www.drupal.org/user/3611858
[5] https://www.drupal.org/user/3455737
[6] https://www.drupal.org/user/36762
[7] https://www.drupal.org/user/272316
[8] https://www.drupal.org/u/cilefen

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] Tarte au Citron - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-064, security-news, 27.11.2024

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang