Drupal getting a little paranoid ?!? (module remove related)

TinTin_Pinguin - September 18, 2008 - 15:06

Today I received another SA from Drupal.
This time, the “security team” is just telling us that the “answers” module is having some Xss inside and ask us to remove de module! The module page is getting an “access deny” nice error.

No explanation, no nothing.

Just remove and go home.

Some site owners do use this module online.
For them, this action may look a little bit not polite, at least.

Wander if THIS is Open Source spirit these days?

Tintin

Was this a drupal designed mod?

ctkscout - September 18, 2008 - 15:12

Is this a mod that Drupal designed themselves or a contributor?

Charlie

Decision

TinTin_Pinguin - September 18, 2008 - 15:18

I would say that the decision “owner” would be the subject here.
Who made that brilliant decision and why?
I am sure there is a very good reason, just wander if this should be a secret for the community.

a little more explanation

greggles - September 19, 2008 - 03:19

Hello TinTin_Pinguin,

I think you're overreacting and stating things that are not true. The explanation is right here.

The security team always first tries to work with the module maintainer to come up with a solution that will allow users to keep using a module. However, sometimes this is not possible (the maintainer doesn't respond, or doesn't understand our advice).

In these situations the solution we are forced to choose is to let site users know that the module is insecure and no longer supported and prevent future users from downloading the insecure module.The Update Status module (contributed module for Drupal 5, core for Drupal 6) will alert users that a module is unsupported if the project nodes are unpublished.

In this case, the answers module could be easily re-created using the cck module and perhaps a few other small modules.

Is this paranoid? Well, that's up to you. You are always welcome to continue using a module that has security holes in it, that's always your freedom.

Can you state what you think the security team should have done? Keep in mind that it is overworked and understaffed so any solution like "fix the module themselves" or "provide an upgrade to a new system" is simply not feasible.

--
Growing Venture Solutions | Drupal Dashboard | Learn more about Drupal - buy a Drupal Book

 
 

Drupal is a registered trademark of Dries Buytaert.