This page displays all public Tag1 D7ES announcements, including security advisories and compatibility updates. You may filter below by announcement type, project, and subscribe to that customized RSS feed at the bottom of the page.

 

Field Collection - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-1.3
The Field Collection module granted users with the "edit field collections" permission unconditional access to field collection items, bypassing parent entity access checks entirely. A separate flaw allowed access when the host entity could not be loaded, as passing NULL to "entity_access()" may return TRUE for some entity types.

LDAP Authentication - Moderately Critical - Information Disclosure

Date
Severity
Less Critical
Affected versions
<7.x-2.7
The LDAP Authentication module logged the LDAP bind password in plaintext to Drupal's watchdog system whenever a non-anonymous bind failed, potentially exposing service account credentials to anyone with access to the site's log reports.

OpenID Connect - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-1.4
The OpenID Connect module introduced a prompt parameter configuration that, when misconfigured, could potentially weaken authentication security by allowing users to bypass certain authentication requirements through OpenID Connect identity providers.

OpenID Connect - Moderately Critical - Server Side Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-1.4
The OpenID Connect module contained a Server Side Request Forgery (SSRF) vulnerability in its user picture handling functionality, allowing attackers to force the server to make HTTP requests to arbitrary URLs through malicious user picture URLs.

OpenID Connect - Less Critical - Email Uniqueness Validation

Date
Severity
Moderately Critical
Affected versions
<7.x-1.4
The OpenID Connect module contained an email uniqueness validation vulnerability that allowed duplicate user accounts to be created with email addresses that differ only in case, potentially leading to account confusion and authentication bypass scenarios.