Date
Severity
Moderately Critical
Vulnerability
Access Bypass
Affected versions
<7.x-3.3

Description

The Deploy remote Cache clear submodule of the Deploy Content Staging module exposes a Services resource action that clears all caches on the server.

The module does not check any permission before running the cache clear operation because its access callback always grants access, so any unauthenticated remote client that can reach the Services endpoint can force a full site cache flush.

This vulnerability is mitigated by the fact that the submodule is not enabled by default and requires a Services endpoint that exposes the remote cache clear resource to be configured on the server.

Solution

Install the latest version.

If you use the Deploy module for Drupal 7, upgrade to Deploy 7.x-3.3:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES