This page displays all public Tag1 D7ES announcements, including security advisories and compatibility updates. You may filter below by announcement type, project, and subscribe to that customized RSS feed at the bottom of the page.

 

Profile Module Manager - Less Critical - Cross Site Scripting

Date
Severity
Less Critical
Affected versions
<7.x-2.2
The bundle confirmation page prints the names of currently logged in users directly into the page markup without sanitisation, so a username that contains HTML can execute script in the browser of any bundle manager who views the confirmation page.

Adaptive Image - Less Critical - Denial of Service

Date
Severity
Less Critical
Affected versions
<7.x-1.5
The module's image delivery callback does not verify that the source image exists before attempting derivative generation, causing the server to acquire a database lock, invoke the image toolkit, and return a 500 Internal Server Error for any request targeting a non-existent source file.

Drupal core - Moderately Critical - Information Disclosure

Date
Severity
Moderately Critical
Affected versions
<7.106
The Image module does not check access to image style derivatives when the derivative is stored on a file scheme other than the core private scheme, so an anonymous visitor who obtains a valid derivative URL can download derivatives of images that a contributed stream wrapper is meant to keep protected.

Image Editor - Moderately Critical - Reflected Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
<7.x-1.14
The Snipshot and FotoFlexer editor save callbacks in the Image Editor module place an image value taken from the request query string into an inline JavaScript string without encoding it, allowing an attacker to run arbitrary JavaScript in the browser of a victim who follows a crafted link.

Image Editor - Less Critical - Local File Disclosure

Date
Severity
Less Critical
Affected versions
<7.14
The Image Editor module resolves a file location supplied by the user in a POST parameter and passes it to cURL as an upload field without confining it to the site files directory. On PHP versions before 5.6, where cURL's legacy file upload mechanism is active, this lets an authenticated user make the server read an arbitrary local file, such as settings.php, and transmit its contents to an external image service. On PHP 5.6 and later the legacy mechanism is disabled, so no file contents are disclosed and the practical impact is limited to a forced outbound request.

Image Editor - Critical - Path Traversal

Date
Severity
Critical
Affected versions
<7.x-1.14
The Image Editor module builds the destination path for a fetched image out of client supplied filename and extension values without sanitizing them, allowing an authenticated user to write the fetched content to an arbitrary location with an arbitrary extension, including an executable PHP file inside the public files area, which can lead to remote code execution.

Services - Moderately Critical - Stored Cross Site Scripting via Unvalidated File Uploads

Date
Severity
Moderately Critical
Affected versions
<7.x-3.30
The REST API file upload endpoints validate files by extension only, so an authenticated user can store a non-image file (such as HTML containing JavaScript) with an image extension and later reference it from an image field, leading to stored cross site scripting.

Image Editor - Moderately Critical - Cross-Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-1.14
The Image Editor module doesn't protect two state-changing AJAX endpoints against cross-site request forgery, allowing an attacker to trick a logged-in user who holds the relevant permission into performing an unauthorized image upload or image file overwrite without their intent.

Deploy - Content Staging (Remote Cache Clear) - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-3.3
The Deploy remote Cache clear submodule registers a Services resource whose access callback unconditionally grants access, allowing any unauthenticated remote user to trigger a full cache flush on the server. Repeatedly invoking this operation can degrade performance and cause a denial of service.