Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] CookieCuttr - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-181

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] CookieCuttr - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-181


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] CookieCuttr - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-181
  • Date: Wed, 23 Sep 2026 17:08:12 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=gYR21nMV; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=4nopZaWh; arc=none smtp.remote-ip=54.240.27.35
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 3FC4E437C3
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org EACAE606BD
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790186600; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=OoBH3vcODlYAtXa0mQ143aagwl5F0FgJPq488SxdlaU=; b=FuPnwv2QYaC6NmeHQ6+j09aARZ32T4WtvQcZ792d2bZ3IMtl+aWAntS5Rr060bxWt74z 0dIAEXfBT7UVRKM3gYudYwtxVQxW+D61BeiRdEsNi29YDPsMakBkUIxDyK7g+BYCTN2SX oNiGjPB6xo2EOYVvouJGiozTq16Pozx6prTNH6mhFdrI3y4dS/gEzVm7d1dTN+YsVNXMM gyczT3vfoptTBZR/IIw3Z2tdSIJ6gigrNZka15c7gLBB+axi4NH8IHuHkSHhXYPGXIL5A Q66xvheqjBsC6YmTojYAd56smjBCBLtO91FkYrwD3t5LVQ0gAeoNvTR7WtEN7M1QMiA==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790183293; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=yrP4u/2EssAF49cuHR9IdGEVMtAxvIif3tGfUnM9MLI=; b=pd4h+QvIcJN4dBmVLSbJq00QCQpcO9LqOTwTjIGtvcePeoNvHePwUe0G3PqbyMUAwI9M sZ+memKqT1/BC0SMQqboZPl7V+yJqRmfqb7hPoBQ0BlU3aqe9KwILXQVOBeX+Mg2bj889 Pms85Yb9SrvjjcdocU/D6kjmmCVE5sN1r/J52gT439h1II4bGp81PuTqH5TQm2J2atdxy zOdfFnrT4OWN4M6o1LQewzgUT8Xz7QEioL+i5KKvbTAGMjfWOu65/Wlx9ItMWO8tuH2eJ SAmujZMY+iVDMFQwUwWCiLG6Fuvy3vfZP0u/zi4svZtbErgchFWN4Y2z+DykcgpKgQA==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790186600; b=nQEUU1EGdUnB+wAVdQlkKBQTepwimb01IobdjcF65RrSReSljR/rqfQkk3oM+djRweJ8 1R6hJv6BmNmXe0mmPEmZQK+WGoi2UBTQOTr3/xV+e81+3E6rWoD1Odz6EbweZRYwYsUv1 IIwMRNP0IElS9KolNc8l0/olt/i08su801Y2LUtV75xDrFKetXbWqC+TrZqM6cZK+Ii3s 67MWACphWRx1dgL+xX5D9eHmexizP4Ao7zIWjgbdpIJY1ib0NGnPJJy643oMj6NHcEfAp bgcazflxD7Qjne+SBXdV1jiyoEsyfPWEVivqOYXdRCUBJaVmtz2Ou3Rt+H6TKrYeVfQ==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790183293; b=acfb6PdzY01W1R8xZJoDHHcS5nXl0eoScKVkuJMVTOShJOVBRqV83sUst0wbONcyrqkj As5TowjqlZ3P8x+9zmisHygtE5foic3FTr2o8XA08vmJZYUT18pSFoYpi7T6B07pGraBr L4IkYWut1Tdj8hiGlfgiW1SjR03vaPukgwNxfvChkHaproLkIWefyRH3LUfyfwcYH5KjI kwoSpWwElnMFBZR3YQNQ0nQhQ2DmwLXzTYutHYDiP8m4i+HdJhLvULOJaKLiIRohYOcFC sKfw6sIwBggK8OO0NefAZvETz2xgNpBahveB3dTfCxANoUlc57clZywM+Hr/Fo2yNFA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/HWXHVZYSKFOMNI4E6R5G6YXWSBATAPRN/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=OCj5PJkE; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=gYR21nMV; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=4nopZaWh; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-181

Project: CookieCuttr [1]
Project machine name: cookiecuttr
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross-site scripting

Affected versions: >=2.0.0 <2.0.3
CVE IDs: CVE-2026-96379
Description: 
This module enables you to provide information and options about cookie
usage.

The module does not sufficiently filter input submitted through the
Cookiecuttr administration form. This could allow specially crafted values to
be stored and later rendered without adequate sanitization, resulting in a
cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role
with the permission /administer cookiecuttr/.

Solution: 
Install the latest version:

* Upgrade to cookiecuttr 2.0.3 [3].

Reported By: 
* Swan Kalata (akalata) [4] of the Drupal Security Team
* Marcus Johansson (marcus_johansson) [5]

Fixed By: 
* Malcolm Young (malcomio) [6]

Coordinated By: 
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Bram Driesen (bramdriesen) [8] of the Drupal Security Team
* Greg Knaddison (greggles) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [11]

[1] https://www.drupal.org/project/cookiecuttr
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/cookiecuttr/releases/2.0.3
[4] https://www.drupal.org/u/akalata
[5] https://www.drupal.org/u/marcus_johansson
[6] https://www.drupal.org/u/malcomio
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/bramdriesen
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/xjm
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3622912

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] CookieCuttr - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-181, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang