Date
Severity
Moderately Critical
Vulnerability
Cross Site Request Forgery
Affected versions
<7.x-2.36

Description

The Open Atrium Notifications module provides notification subscriptions for Open Atrium content, letting users, groups, and teams be notified about activity within a space.

The module deletes a notification subscription from a simple GET request in its remove callback and never validates the security token that the remove links already carry, so the token offers no protection.

This vulnerability is mitigated by the fact that an attacker must lure an authenticated victim into loading a crafted request while the victim session is active.

Solution

Install the latest version.

If you use the Open Atrium Notifications module for Drupal 7, upgrade to Open Atrium Notifications 7.x-2.36:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES