Open Social - Moderately critical - Access bypass - SA-CONTRIB-2021-001
Project: Open Social Versions: 8.x-9.x-dev, 8.x-8.x-dev Date: 2021-January-27 Security risk: Moderately critical 12∕25 Vulnerability: Access bypass
The optional Social Auth Extra module enables you to use the single sign-on methods provided by Open Social e.g. Facebook, LinkedIn, Google and Twitter.
The module doesn't implement a proper cache strategy for anonymous users allowing the registration form to be cached with disclosed information in certain scenarios. The information is usually only available for logged-in users of the community.
This vulnerability is mitigated by the fact that
social_auth_extra needs to be enabled, one of the single sign-on methods needs to be configured. There is no impact for regular registration without single sign-on.
Removing the single sign-on providers from configuration will allow this vulnerability to be blocked.
Install the latest version: