Description
The Token Content Access module restricts access to entities such as nodes, so that a protected entity can only be viewed when a secret access token is supplied as a query parameter in the URL.
The module compares the token supplied in the URL against the token stored for the entity using a loose comparison, which stops at the first character that differs, so the time the comparison takes reveals how many leading characters of the token were correct, and which also treats any two values that PHP reads as the same number as equal even when they are different strings.
This vulnerability is mitigated by the fact that an attacker must already know the URL of a protected entity, that the timing difference is far smaller than the normal variation between requests, and that the tokens the module generates are long random values that PHP does not read as a number.
Solution
Install the latest version.
If you use the Token Content Access module for Drupal 7, upgrade to Token Content Access 7.x-1.1:
Reported by
Fixed by
- Kyrylo Loboda (lobodakyrylo)
- Tag1 D7ES
Coordinated by
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Tag1 D7ES