Date
Severity
Less Critical
Vulnerability
Unrestricted File Upload
Affected versions
<7.x-6.7

Description

The Brightcove Video Connect module provides a video upload form that lets a user supply poster and thumbnail images alongside the video before it is sent to Brightcove.

The form validates those images by file extension alone, so a file that carries an image extension but contains an HTML or JavaScript payload passes validation and is saved to the public files directory.

This vulnerability is mitigated by the fact that the upload form requires a privileged role and that Drupal core serves the stored file with an extension derived content type and an X Content Type Options nosniff header, which stops a browser from running the payload as active content.

Solution

Install the latest version.

If you use the Brightcove Video Connect module for Drupal 7, upgrade to Brightcove Video Connect 7.x-6.7:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES