Project
Date
Severity
Moderately Critical
Vulnerability
Moderately Critical
Affected versions
<7.x-2.36
Description
The Open Atrium Notifications module provides notification subscriptions for Open Atrium content, letting users, groups, and teams be notified about activity within a space.
The module deletes a notification subscription from a simple GET request in its remove callback and never validates the security token that the remove links already carry, so the token offers no protection.
This vulnerability is mitigated by the fact that an attacker must lure an authenticated victim into loading a crafted request while the victim session is active.
Solution
Install the latest version.
If you use the Open Atrium Notifications module for Drupal 7, upgrade to Open Atrium Notifications 7.x-2.36:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES