The AltaGrade Blog
WordPress 5.4 “Adderley” is released today
Here it is! Named “Adderley” in honor of Nat Adderley, the latest and greatest version of WordPress is available for download or update in your dashboard.
Svg Image - Critical - Cross site scripting - SA-CONTRIB-2020-008
Project: Svg Image
Date: 2020-March-25
Security risk: Critical 15∕25
Vulnerability: Cross site scripting
Description
SVG Image module allows to upload SVG files.
The module did not sufficiently protect against malicious code inside SVG files leading to a Cross Site Scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must have permission to upload an SVG file.
Solution
Install the latest version:
Backdrop core - Moderately critical - Third-party library - BACKDROP-SA-CORE-2020-001
Security risk: Moderately Critical
Advisory ID: BACKDROP-SA-CORE-2020-001
Vulnerability: Third Party Libraries
Description
The Backdrop project uses the third-party library CKEditor, which has released a security improvement that is needed to protect some Backdrop configurations.
AltaGrade During the Coronavirus Crisis
As the global pandemic of the COVID-19 continues to develop, we wanted to reach out to our current and prospective customers and let you know how AltaGrade is dealing with the Coronavirus emergency.
CKEditor - WYSIWYG HTML editor - Moderately critical - Cross site scripting - SA-CONTRIB-2020-007
Project: CKEditor - WYSIWYG HTML editor
Date: 2020-March-18
Security risk: Moderately critical 11∕25
Vulnerability: Cross site scripting
Description
The CKEditor module (and its predecessor, FCKeditor module) allows Drupal to replace textarea fields with CKEditor 3.x/4.x (FCKeditor 2.x in case of FCKeditor module) - a visual HTML editor, sometimes called WYSIWYG editor.
Drupal 8 core - Moderately critical - Third-party library - SA-CORE-2020-001
Project: Drupal core
Versions: 8.8.x-dev, 8.7.x-dev
Date: 2020-March-18
Security risk: Moderately critical 13∕25
Vulnerability: Third-party library
Description
The Drupal project uses the third-party library CKEditor, which has released a security improvement that is needed to protect some Drupal configurations.
SAML Service Provider - Critical - Access bypass - SA-CONTRIB-2020-006
Project: SAML Service Provider
Date: 2020-March-11
Security risk: Critical 15∕25
Vulnerability: Access bypass
Description
This module enables you to authenticate Drupal users using an external SAML Identity Provider.
If the site is configured to allow visitors to register for user accounts but administrator approval is required, the module doesn't sufficiently enforce the administrative approval requirement, in the case where the requesting user has already authenticated through SAML.
Profile - Moderately critical - Access Bypass - SA-CONTRIB-2020-004
Project: Profile
Date: 2020-February-19
Security risk: Moderately critical 14∕25
Vulnerability: Access Bypass
Description
The Profile module enables you to allow users to have configurable user profiles.
The module doesn't sufficiently check access when creating a user profile. Users with the "create profiles" permission could create profiles for any users.
Solution
Install the latest version:
Views Bulk Operations (VBO) - Moderately critical - Access bypass - SA-CONTRIB-2020-003
Project: Views Bulk Operations (VBO)
Date: 2020-February-05
Security risk: Moderately critical 12∕25
Vulnerability: Access bypass
Description
Views Bulk Operations provides enhancements to running bulk actions on views.
The module contains an access bypass vulnerability that might allow users to execute views actions that they should not have access to.
This vulnerability is mitigated by the fact that it only occurs in the case of customised action access (by means of hook_action_info_alter).