Description
The Geckoboard API module lets other modules expose site data to the Geckoboard dashboard service by registering service callbacks that are served from a single public endpoint.
The endpoint access check reads a secret configuration value under a name that differs from the name the settings form saves it under, so the lookup never finds a stored value and falls back to an empty string, and it then grants access to any request whose Basic authentication username equals that empty string. Because an empty username is trivial to send, an unauthenticated visitor can satisfy the check and cause the endpoint to run every registered service callback and return its data.
This vulnerability is mitigated by the fact that it discloses only the data returned by service callbacks that other modules have registered, and by the requirement that the hosting environment populate the Basic authentication username for the request.
Solution
Install the latest version.
If you use the Geckoboard API module for Drupal 7, upgrade to Geckoboard API 7.x-1.1:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES