Date
Severity
Moderately Critical
Vulnerability
Access Bypass
Affected versions
<7.x-3.3
Description
The Deploy remote Cache clear submodule of the Deploy Content Staging module exposes a Services resource action that clears all caches on the server.
The module does not check any permission before running the cache clear operation because its access callback always grants access, so any unauthenticated remote client that can reach the Services endpoint can force a full site cache flush.
This vulnerability is mitigated by the fact that the submodule is not enabled by default and requires a Services endpoint that exposes the remote cache clear resource to be configured on the server.
Solution
Install the latest version.
If you use the Deploy module for Drupal 7, upgrade to Deploy 7.x-3.3:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES