Drupal Core – Moderately Critical – Multiple Vulnerabilities – SA-CORE-2016-002

rfp-robotRFP ROBOT: Website Request for Proposal Generator

The time has come for a new website (or website redesign), which means you need to write a website request for proposal or web RFP. A Google search produces a few examples, but they vary wildly and don’t seem to speak really to your goals for developing or redesigning a new website. You need to write a website RFP that will clearly articulate your needs and generate responses from the best website designers and developers out there. But how?

Have no fear, RFP Robot is here. He will walk you through a step-by-step process to help you work through the details of your project and create a PDF formatted website design RFP that will provide the information vendors need to write an accurate bid. RFP Robot will tell you what info you should include, point out pitfalls, and give examples.


Advisory ID: DRUPAL-SA-CORE-2016-002
Project: Drupal core
Version: 7.x, 8.x
Date: 2016-June-15
Security risk: 11/25 ( Moderately Critical) AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon
Vulnerability: Access bypass, Multiple vulnerabilities
Description
Saving user accounts can sometimes grant the user all roles (User module – Drupal 7 – Moderately Critical)
A vulnerability exists in the User module, where if some specific contributed or custom code triggers a rebuild of the user profile form, a registered user can be granted all user roles on the site. This would typically result in the user gaining administrative access.
This issue is mitigated by the fact that it requires contributed or custom code that performs a form rebuild during submission of the user profile form.
Views can allow unauthorized users to see Statistics information (Views module – Drupal 8 – Less Critical)
An access bypass vulnerability exists in the Views module, where users without the “View content count” permission can see the number of hits collected by the Statistics module for results in the view.
This issue is mitigated by the fact that the view must be configured to show a “Content statistics” field, such as “Total views”, “Views today” or “Last visit”.
The same vulnerability exists in the Drupal 7 Views module (see SA-CONTRIB-2016-036).

CVE identifier(s) issued
Saving user accounts can sometimes grant the user all roles: CVE-2016-6211
Views can allow unauthorized users to see Statistics information: CVE-2016-6212
Versions affected
Drupal core 7.x versions prior to 7.44
Drupal core 8.x versions prior to 8.1.3
Solution
Install the latest version:
If you use Drupal 7.x, upgrade to Drupal core 7.44
If you use Drupal 8.x, upgrade to Drupal core 8.1.3
Also see the Drupal core project page.
Reported by
Saving user accounts can sometimes grant the user all roles:
alfaguru
Views can allow unauthorized users to see Statistics information:
Nickolay Leshchev
Fixed by
Saving user accounts can sometimes grant the user all roles:
Ben Dougherty of the Drupal Security Team
Balazs Nagykekesi
David Rothstein of the Drupal Security Team
Lee Rowlands of the Drupal Security Team
Stefan Ruijsenaars of the Drupal Security Team
vlad.k
Peter Wolanin of the Drupal Security Team
Views can allow unauthorized users to see Statistics information:
Nathaniel Catchpole of the Drupal Security Team
Greg Knaddison of the Drupal Security Team
Nickolay Leshchev
Stefan Ruijsenaars of the Drupal Security Team
David Snopek of the Drupal Security Team
Daniel Wehner
xjm of the Drupal Security Team
Coordinated by
The Drupal Security Team
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.
Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.
Follow the Drupal Security Team on Twitter at https://twitter.com/drupalsecurity
Drupal version: Drupal 7.xDrupal 8.x
Drupal Developer

Posted on June 15, 2016 in Austin Web Designer, Drupal Developer, Drupal Development Austin, Drupal in Austin, Expert Drupal Development, Web Design Services

Share the Story

Back to Top