This page displays all public Tag1 D7ES Security Advisories. Check out our Announcements page for all updates.

You can filter this list by project or subscribe to the RSS feed.

 

Field Collection - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-1.3
The Field Collection module granted users with the "edit field collections" permission unconditional access to field collection items, bypassing parent entity access checks entirely. A separate flaw allowed access when the host entity could not be loaded, as passing NULL to "entity_access()" may return TRUE for some entity types.

Export Logs - Moderately Critical - CSV Injection

Date
Severity
Moderately Critical
Affected versions
<7.x-1.5
The Export Logs module was vulnerable to CSV injection attacks where log field values containing formula-starting characters were written to CSV files without sanitization, allowing malicious formulas to execute when the exported file was opened in a spreadsheet application.

TableField - Moderately Critical - CSV Injection

Date
Severity
Moderately Critical
Affected versions
<7.x-3.6
The TableField module was vulnerable to CSV injection attacks where table cell values containing formula-starting characters were written to exported CSV files without sanitization, allowing malicious formulas to execute when the file was opened in a spreadsheet application.

FileField Sources - Moderately Critical - Server-Side Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-1.12
The FileField Sources module's remote URL source allows authenticated users to supply arbitrary URLs that are fetched via cURL. Before the fix, no restrictions prevented those URLs from targeting internal or reserved IP addresses, or from using non-HTTP schemes, enabling attackers to probe or interact with internal network services.

Login One Time - Less Critical - Information Disclosure

Date
Severity
Less Critical
Affected versions
<7.x-2.11
The module has been updated to use consistent error messaging for all login failure cases. Instead of using "drupal_access_denied()", the module now displays a generic error message: "You have tried to use a one-time login link that is invalid or has expired. Please use the log in form to supply your username and password." and redirects users to the login page.

HybridAuth - Moderately Critical - Server Side Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-2.17
The HybridAuth Social Login module contained a Server Side Request Forgery (SSRF) vulnerability in its user picture handling functionality, allowing attackers to force the server to make HTTP requests to arbitrary URLs by supplying a malicious picture URL through a controlled social identity provider.

LDAP Authentication - Moderately Critical - Information Disclosure

Date
Severity
Less Critical
Affected versions
<7.x-2.7
The LDAP Authentication module logged the LDAP bind password in plaintext to Drupal's watchdog system whenever a non-anonymous bind failed, potentially exposing service account credentials to anyone with access to the site's log reports.

OpenID Connect - Less Critical - Email Uniqueness Validation

Date
Severity
Moderately Critical
Affected versions
<7.x-1.4
The OpenID Connect module contained an email uniqueness validation vulnerability that allowed duplicate user accounts to be created with email addresses that differ only in case, potentially leading to account confusion and authentication bypass scenarios.