Date
Severity
Moderately Critical
Vulnerability
Timing Attack
Affected versions
<7.x-1.1

Description

The Token Content Access module restricts access to entities such as nodes, so that a protected entity can only be viewed when a secret access token is supplied as a query parameter in the URL.

The module compares the token supplied in the URL against the token stored for the entity using a loose comparison, which stops at the first character that differs, so the time the comparison takes reveals how many leading characters of the token were correct, and which also treats any two values that PHP reads as the same number as equal even when they are different strings.

This vulnerability is mitigated by the fact that an attacker must already know the URL of a protected entity, that the timing difference is far smaller than the normal variation between requests, and that the tokens the module generates are long random values that PHP does not read as a number.

Solution

Install the latest version.

If you use the Token Content Access module for Drupal 7, upgrade to Token Content Access 7.x-1.1:


Reported by

Fixed by

Coordinated by