The AltaGrade Blog

Drupal 7: Internationalization - Moderately critical - Cross site scripting - SA-CONTRIB-2020-025

Drupal Security

Project: Internationalization
Version: 7.x-1.x-dev
Date: 2020-June-17
Security risk: Moderately critical 14∕25 
Vulnerability: Cross site scripting

Description

The Internationalization (i18n) module is a collection of modules to extend Drupal 7 core multilingual capabilities and allows to build real life multilingual sites.

A value in the term translation module is displayed without being escaped leading to a Cross Site Scripting (XSS) vulnerability.

Read More

Drupal 8 and 9 core - Less critical - Access bypass - SA-CORE-2020-006

Drupal Security

Project: Drupal core
Date: 2020-June-17
Security risk: Less critical 8∕25 
Vulnerability: Access bypass
CVE IDs: CVE-2020-13665

Description

JSON:API PATCH requests may bypass validation for certain fields.

By default, JSON:API works in a read-only mode which makes it impossible to exploit the vulnerability. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable.

Solution

Install the latest version:

Read More

Drupal 8 and 9 core - Critical - Arbitrary PHP code execution - SA-CORE-2020-005

Drupal Security

Project: Drupal core
Date: 2020-June-17
Security risk: Critical 17∕25 
Vulnerability: Arbitrary PHP code execution
CVE IDs: CVE-2020-13664

Description

Drupal 8 and 9 have a remote code execution vulnerability under certain circumstances.

An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability.

Read More

Open ReadSpeaker - Moderately critical - Cross site scripting - SA-CONTRIB-2020-024

drupal hosting

Project: Open ReadSpeaker
Version: 8.x-1.x-dev
Date: 2020-June-10
Security risk: Moderately critical 13∕25 
Vulnerability: Cross site scripting

Description

This module enables you to add a configured ReadSpeaker button for text-to-speech for your site visitors.

The module doesn't sufficiently sanitize block configuration causing a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer blocks".

Read More

WordPress 5.4.2 has been released

WordPress hosting

This security and maintenance release features 22 fixes and enhancements. Plus, it adds a number of security fixes—see the list below.

These bugs affect WordPress versions 5.4.1 and earlier; version 5.4.2 fixes them, so you’ll want to upgrade.

If you haven’t yet updated to 5.4, there are also updated versions of 5.3 and earlier that fix the bugs for you.

Security Updates

Read More

Services for Drupal 7- Moderately critical - Access bypass - SA-CONTRIB-2020-022

Services for Drupal 7- Moderately critical - Access bypass - SA-CONTRIB-2020-022

Project: Services
Version: 7.x-3.x-dev
Date: 2020-June-03
Security risk: Moderately critical 11∕25
Vulnerability: Access bypass

Description

This module provides a standardized solution for building API's so that external clients can communicate with Drupal.

The module's taxonomy term index resource doesn't take into consideration certain access control tags provided (but unused) by core, that certain contributed modules depend on.

Read More

Drupal 7.71 has been released today

Drupal 7.71 has been released today

Drupal 7.71 has been released today on 3 June 2020. This maintenance release of the Drupal 7 series includes bug fixes and small API/feature improvements. It does not have any major, non-backwards-compatible new functionalities. No security fixes are included in this release either.

Read More

Pages