Needs review
Project:
Admin:hover
Version:
6.x-1.x-dev
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Reporter:
Created:
16 Jan 2012 at 22:13 UTC
Updated:
30 May 2012 at 08:09 UTC
The attached patch adds token verification for the SA-CONTRIB-2012-006 CSRF vulnerability. This method was chosen so as not to change the flow of the module, in case others were depending upon this behaviour. An alternative patch is available that uses a confirmation dialogue instead. Comments, criticism welcome.
| Comment | File | Size | Author |
|---|---|---|---|
| admin_hover-csrf-sa-contrib-2012-006.patch | 1.47 KB | ajdonnison |
Comments
Comment #1
ajdonnison commentedPatch added to 6.x-1.x tree, waiting on security review before releasing new version.
Comment #3
sittard commentedDid this patch ever get reviewed by the security team? The project status page is still showing 'abandoned'.
Thanks.
Comment #4
ajdonnison commentedI sent details based on the abandoned projects process, but didn't hear back. Setting back to needs review. This of course could be my fault for not fully understanding the process rather than the process itself.
Comment #5
hansrossel commentedDid you send an email to security@drupal.org with the patch? They normally reply very quickly. Did you follow the procedure http://drupal.org/node/101497?
Seems like a misunderstanding here as you a few days after the security bug posted a patch here while it should have been sent to the security team instead and the patch discussed and agreed with them. I suppose an email to them should be enough to clarify this misunderstanding and get the module up again.