Biztonsági figyelmeztetések
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003
Drupal uses JavaScript to render status messages in some cases and configurations. In certain situations, the status messages are not adequately sanitized.
Solution:Install the latest version:
- If you are using Drupal 10.2, update to Drupal 10.2.11.
- If you are using Drupal 10.3, update to Drupal 10.3.9.
- If you are using Drupal 11.0, update to Drupal 11.0.8.
All versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
Reported By: Fixed By:- Lee Rowlands of the Drupal Security Team
- catch of the Drupal Security Team
- Mingsong
- Juraj Nemec of the Drupal Security Team
- Dave Long of the Drupal Security Team
- Benji Fisher of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team
Node export - Moderately critical - Arbitrary PHP code execution - SA-CONTRIB-2024-061
This module allows users to export nodes and then import it into another Drupal installation, or on the same site.
In certain cases the module doesn't sufficiently sanitize data before passing it to PHP's unserialize() function, which could results in Remote Code Execution via PHP Object Injection.
This vulnerability is mitigated by the fact that an attack must operate with the permission "Use PHP to import nodes", however this could be the case if this issue were combined with others in an "attack chain".
In general, if this module is not in active use it is recommended to disable it.
Solution:Install the latest version:
- If you use the Node Export module for Drupal 7, upgrade to Node Export 7.x-3.3
- Drew Webber of the Drupal Security Team
- Drew Webber of the Drupal Security Team
- Ivan Trokhanenko
- Drew Webber of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team
POST File - Critical - Cross Site Scripting, Arbitrary PHP code execution - SA-CONTRIB-2024-060
The module creates an endpoint on the site at /postfile/upload that accepts a POST request for uploading a single file into a specified file system (public, private, etc).
This module accepts any uploaded file extension, including dangerous file formats so it can be used to bypass the allow_insecure_uploads config.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "postfile upload".
Solution:Install the latest version:
- If you use the POST File module for Drupal 10.3.x/11.x, upgrade to POST File 1.0.2
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
POST File - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-059
The module creates an endpoint on the site at /postfile/upload that accepts a POST request for uploading a single file into a specified file system (public, private, etc).
The module doesn't sufficiently protect against Cross Site Request Forgery
under allowing an attacker to trick a site user into uploading a file.
Install the latest version:
- If you use the POST File module for Drupal 10.3.x/11.x, upgrade to Post File 1.0.2
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
Tooltip - Moderately critical - Cross site scripting - SA-CONTRIB-2024-058
This module enables you to add any HTML content you want in a tooltip displayed on mouse hover.
The module does not sufficiently escape the markup inserted in the tooltip block.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer blocks".
Solution:Install the latest version:
- If you use the Tooltip module for Drupal 8.x, 9.x or 10.x, upgrade to Tooltip 1.1.2
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
- Ivo Van Geertruyen of the Drupal Security Team
Basic HTTP Authentication - Critical - Access bypass - SA-CONTRIB-2024-057
The module provides a possibility to restrict access to specific paths using
basic HTTP authentication, in addition to standard Drupal access checks.
In some cases, the module removes existing access checks from some paths, resulting in an access bypass vulnerability.
Solution:Install the latest version:
- If you use the Basic HTTP Authentication module for Drupal 7.x, upgrade to Basic Authentication 7.x-1.4
- Roderik Muit
- Ivo Van Geertruyen of the Drupal Security Team
- Ivo Van Geertruyen of the Drupal Security Team
OhDear Integration - Moderately critical - Access bypass - SA-CONTRIB-2024-056
Integrates your Drupal website with the Oh Dear monitoring app.
Cached data of monitoring results is accessible to non-logged in users when caching is enabled on the module.
This vulnerability is mitigated by the fact that it only affects sites where caching is enabled for OhDear report healthcheck endpoint. It is not enabled by default and there's no UI option to do it. It has to be done directly in the ohdear_integration.settings.yml.
Solution:Install the latest version:
- If you use the OhDear Integration module, upgrade to 2.0.4 version.
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
Cookiebot + GTM - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-055
This module makes it possible for you to integrate Cookiebot and Google Tag Manager in a fast and simple way.
The module doesn't sufficiently filter for malicious script leading to a persistent cross site scripting (XSS) vulnerability.
Solution:Install the latest version and review settings:
- If you use the Cookiebot + GTM module for Drupal, upgrade to Cookiebot + GTM 1.0.18
- Additionally, the new codebase adds validation and permission changes so admins should re-save the configuration form at /admin/config/cookiebot_gtm and confirm which roles have permission to configure the module at /admin/people/permissions.
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
- Cathy Theys of the Drupal Security Team
Loft Data Grids - Moderately critical - Multiple vulnerabilities - SA-CONTRIB-2024-054
This module provides serialization formats for use by other modules.
The module includes a version of phpoffice/phpspreadsheet which has multiple known security vulnerabilities.
Solution:If you use the Loft Data Grids module for Drupal 7.x, install one of:
- Loft Data Grids 7.x-2.7 - which removes support for the XLSX format, as the patched version requires PHP 8.
- Loft Data Grids 7.x-3.0 - which includes XLSX support, by requiring PHP 8 and Composer installation. See the module's README-file for more information.
- Juraj Nemec of the Drupal Security Team
Smartling Connector - Less critical - Multiple vulnerabilities - SA-CONTRIB-2024-053
Smartling module allows you to translate content in Drupal 7 using the Smartling Translation Management Platform.
The module includes an outdated version of the Guzzle package (guzzlehttp/guzzle 6.3.3), which has known security vulnerabilities.
Solution:Install the latest version:
- If you use Smartling module for Drupal 7.x-4.x, upgrade to smartling 7.x-4.19
- If you use Smartling module for Drupal 7.x-3.x, upgrade to smartling 7.x-3.8
- Juraj Nemec of the Drupal Security Team
Monster Menus - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-052
This module enables you to group nodes within pages that have a highly-granular, distributed permissions structure.
In certain cases the module doesn't sufficiently sanitize data before passing it to PHP's unserialize() function, which can result in arbitrary code execution.
Solution:Install the latest version:
- If you use Monster Menus branch 9.4.x, upgrade to monster_menus 9.4.2
- If you use Monster Menus branch 9.3.x, upgrade to monster_menus 9.3.4
- Drew Webber of the Drupal Security Team
- Drew Webber of the Drupal Security Team
- Dan Wilga
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
- Drew Webber of the Drupal Security Team
Views SVG Animation - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-051
This module enables you to animate an SVG graphic by selecting certain rows in a view.
The module doesn't sufficiently sanitize the SVG file before embedding it into the html.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to upload SVG files.
Solution:Install the latest version:
- If you use the views_svg_animation module for Drupal 10 or 11, upgrade to views_svg_animation 1.0.1
- Juraj Nemec of the Drupal Security Team
SVG Embed - Moderately critical - Cross site scripting - SA-CONTRIB-2024-050
This module enables you to embed the content of an SVG file into the body html of a node and optionally allows to translate text contained within the image.
The module doesn't sufficiently sanitize the SVG file before embedding it into the html.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to upload SVG files, and the permission to use a text format that includes the SVG embed filter.
Solution:Install the latest version:
- If you use the svg_embed module for Drupal 7.x, upgrade to svg_embed 7.x-1.3
- If you use the svg_embed module for Drupal 10 or 11, upgrade to svg_embed 2.1.2
- Ivo Van Geertruyen of the Drupal Security Team
- Jürgen Haas
- Ivo Van Geertruyen of the Drupal Security Team
Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002
Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.
The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
Solution:Install the latest version:
- If you are using Drupal 10.2, update to Drupal 10.2.10.
- Drupal 10.3 and above are not affected, nor is Drupal 7.
All versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
This advisory is not covered by Drupal Steward.
Reported By: Fixed By:- catch of the Drupal Security Team
- Lee Rowlands of the Drupal Security Team
- Benji Fisher of the Drupal Security Team
- Kim Pepper
- Wim Leers
- xjm of the Drupal Security Team
- xjm of the Drupal Security Team
- Dave Long of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
wkhtmltopdf - Highly critical - Unsupported - SA-CONTRIB-2024-049
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported
Solution:If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#procedure---own-project---unsupported in full.
Gutenberg - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-048
This module provides a new UI experience for node editing using the Gutenberg Editor library.
The module did not sufficiently protect some routes against a Cross Site Request Forgery attack.
This vulnerability is mitigated by the fact that the tricked user needs to have an active session with the "use gutenberg" permission.
Solution:Install the latest version:
- If you use the Gutenberg module versions 8.x-2.x, upgrade to Gutenberg 8.x-2.13
- If you use the Gutenberg module versions 3.0.x, upgrade to Gutenberg 3.0.5
- Mingsong
- Lee Rowlands of the Drupal Security Team
- Eirik Morland
- Stephan Zeidler
- Cathy Theys of the Drupal Security Team
- codebymikey
- Marco Fernandes
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
Facets - Critical - Cross Site Scripting - SA-CONTRIB-2024-047
This module enables you to to easily create and manage faceted search interfaces.
The module doesn't sufficiently filter for malicious script leading to a reflected cross site scripting (XSS) vulnerability.
Solution:Install the latest version:
- If you use the Facets module, upgrade to Facets 2.0.9
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
Block permissions - Moderately critical - Access bypass - SA-CONTRIB-2024-046
This module enables you to manage blocks from specific modules in the specific themes.
The module doesn't sufficiently check permissions under the scenario when a block is added using the form "/admin/structure/block/add/{plugin_id}/{theme}" (route "block.admin_add"). The attacker can add the block to the theme where they can't manage blocks.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer blocks provided by [provider]".
Solution:Install the latest version:
- If you use the block_permissions module for Drupal 8.x, upgrade to block_permissions version at least 8.x-1.2 or the more recent 8.x-1.3
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
Monster Menus - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-045
This module enables you to group nodes within pages that have a highly-granular, distributed permissions structure.
A function which can be used by third-party code does not return valid data under certain rare circumstances. If the third-party code relies on this data to decide whether to grant access to content, it may grant more access than was intended.
This vulnerability is only present in sites that have custom code calling the mm_content_get_uids_in_group() function with a single UID of zero (0) in the second parameter.
Solution:Install the latest version:
- If you use the monster_menus module for Drupal 7.x, upgrade to monster_menus 7.x-1.34.
- If you use the monster_menus module version 9.3.x, upgrade to monster_menus 9.3.2.
- If you use the monster_menus module version 9.4.0 or newer, no change is needed.
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
- Damien McKenna of the Drupal Security Team
Persistent Login - Moderately critical - Access bypass - SA-CONTRIB-2024-044
This module enables users to remain logged in separately from session timeouts.
The module doesn't sufficiently check a user's disabled status when validating cookies.
This vulnerability is mitigated by the fact that an attacker must have an unexpired cookie from a previous successful login.
Solution:Install the latest version:
- If you use the Persistent Login 8.x-1.x, upgrade to Persistent Login 8.x-1.8
- If you use the Persistent Login 2.x, upgrade to Persistent Login 2.2.2
- Greg Knaddison of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
- Drew Webber of the Drupal Security Team