This page displays all public Tag1 D7ES announcements, including security advisories and compatibility updates. You may filter below by announcement type, project, and subscribe to that customized RSS feed at the bottom of the page.

 

Profile Module Manager - Moderately Critical - Cross Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-2.2
The bundle enable menu callback performs state changing actions in response to a simple GET request without validating a token, so a forged link can enable modules and log every other user out of the site on behalf of an authenticated bundle manager.

Adaptive Image - Less Critical - Denial of Service

Date
Severity
Less Critical
Affected versions
<7.x-1.5
The module's image delivery callback does not verify that the source image exists before attempting derivative generation, causing the server to acquire a database lock, invoke the image toolkit, and return a 500 Internal Server Error for any request targeting a non-existent source file.

Geckoboard API - Critical - Access Bypass

Date
Severity
Critical
Affected versions
<7.x-1.1
The access check on the Geckoboard API endpoint compares the HTTP Basic authentication username against a secret that the module never stores under the name it reads, so the secret always resolves to an empty string. Any anonymous visitor who sends an empty Basic authentication username therefore passes the check and reaches the endpoint, which invokes every registered Geckoboard service callback and echoes its JSON output.

Token Content Access - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-1.1
The module checks the access token from the URL against the token stored for the entity with a comparison that returns as soon as it reaches a character that does not match, so the time the request takes depends on how much of the token was guessed correctly. A persistent attacker who knows the URL of a protected entity can measure that difference to recover a valid token one character at a time and read content they should not be able to see, and the same comparison also accepts any token that PHP reads as the same number as the stored one.

Mail Logger - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-1.8
The Mail Logger module previews the stored body of a logged mail that contains markup as a live document inside an unrestricted inline frame, allowing a visitor who can get markup into the body of an outgoing mail to run arbitrary JavaScript in the origin of the site and in the session of any user who opens that log entry.

Adaptive Image - Critical - Access Bypass

Date
Severity
Critical
Affected versions
<7.x-1.6
The module's image delivery callback is a copy of a Drupal core function that checks access only when the requested file is in the private file system, and the copy also omits the derivative token validation that the original performs. An unauthenticated visitor can request a derivative of an image in the temporary file system, or in any stream wrapper provided by another module, and the module generates and returns it without consulting any access check and without requiring a token.

Instagram Social Feed - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-1.6
The Instagram Social feed module does not restrict access to its photo approval AJAX callback and does not protect it with a request token, allowing any unauthenticated visitor to toggle the publication status of imported photos with a single crafted request.

Commerce PayPal - Moderately Critical - Payment Validation Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-2.7
The Payflow Link payment gateway records a payment from the data posted back to the customer return URL without confirming the transaction with PayPal. A customer can submit a crafted return request to mark their own order as paid without any payment being taken.

File Force Download - Critical - Access Bypass

Date
Severity
Critical
Affected versions
<7.x-1.3
The module grants access to any file that is not in the private file system by returning download headers for it, without asking any other module whether the current user is allowed to read that file. An unauthenticated visitor who appends the module's download parameter to a file URL receives files from the temporary file system or from any stream wrapper supplied by another module, overriding the access checks those modules would otherwise apply.