ldap_integration 6.x-1.0-beta2
miglius - October 27, 2009 - 14:37
| Download | Size | md5 hash |
|---|---|---|
| ldap_integration-6.x-1.0-beta2.tar.gz | 42.13 KB | 2667c3e0c384fd3cb4a5ef0525d0578e |
Official release from CVS tag: DRUPAL-6--1-0-BETA2
Last updated: October 27, 2009 - 14:41
This release fixes:
* The LDAP integration module does not implement a confirmation pages for the LDAP server activation/deactivation which could cause a CSRF attack.
* A user defined server name is not properly escaped on the administration pages which might lead to a XSS attacks.
* The user's LDAP data is not properly access controlled before displaying it in the user profile pages which allows unauthorized view of the data.
* Some user management access rules are ignored during the authentication process.
