Show advisories for only Drupal core, only PSAs, or all security advisories

Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by community members.

Fast Autocomplete - Moderately critical - Access bypass - SA-CONTRIB-2021-005

Project machine name: 
fac
Date: 
2021-March-17

The Fast Autocomplete module provides fast IMDB-like suggestions below a text input field. Suggestions are stored as JSON files in the public files folder so that they can be provided to the browser relatively fast without the need for Drupal to be bootstrapped.

The module doesn't correctly generate certain hashes when the configuration option "Perform search as anonymous user only" is switched from the default on value to off.

Webform - Moderately critical - Access bypass - SA-CONTRIB-2021-004

Project machine name: 
webform
Date: 
2021-March-03

The Webform module for Drupal 8/9 includes a default Contact webform, which sends a notification email to the site owner and a confirmation email to the email address supplied via the form.

The confirmation email can be used as an open mail relay to send an email to any email address.

Subgroup - Less critical - Access bypass - SA-CONTRIB-2021-003

Project machine name: 
subgroup
Date: 
2021-January-27

This module enables you to add groups to other groups in a tree structure where access can be inherited up or down the tree.

When you configure Subgroup to have a tree with at least three levels, users may inadvertently get permissions in a group that is an uncle or cousin of the source group, rather than a direct ancestor or descendant. Trees with only multiple nodes at the lowest tier (or nowhere) are unaffected.

Open Social - Moderately critical - Access bypass - SA-CONTRIB-2021-002

Project machine name: 
social
Date: 
2021-January-27

The Social User Export module enables users within Open Social to create an export of users and download this to a CSV file.

The module doesn't sufficiently check access when building the CSV file, allowing logged-in users without the manage members permission to be able to export all data from a selected user in certain scenarios.

This vulnerability is mitigated by the fact that an attacker must have the authenticated user role and the site must have the configuration set in such a way a logged in user is able to export users.

Open Social - Moderately critical - Access bypass - SA-CONTRIB-2021-001

Project machine name: 
social
Date: 
2021-January-27

The optional Social Auth Extra module enables you to use the single sign-on methods provided by Open Social e.g. Facebook, LinkedIn, Google and Twitter.

The module doesn't implement a proper cache strategy for anonymous users allowing the registration form to be cached with disclosed information in certain scenarios. The information is usually only available for logged-in users of the community.

SAML SP 2.0 Single Sign On (SSO) - SAML Service Provider - Critical - Access bypass - SA-CONTRIB-2020-038

Project machine name: 
miniorange_saml
Date: 
2020-November-18

This module enables your users residing at a SAML 2.0 compliant Identity Provider to login to your Drupal website.

The module has two Authentication Bypass vulnerabilities.

Ink Filepicker - Critical - Unsupported - SA-CONTRIB-2020-037

Project machine name: 
media_inkfilepicker
Date: 
2020-November-18

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer.

It looks like the 3rd party service that this module integrates with may have been retired.

If you would like to maintain this project nevertheless, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Examples for Developers - Critical - Remote Code Execution - SA-CONTRIB-2020-035

Project machine name: 
examples
Date: 
2020-November-18

The File Example submodule within the Examples project does not properly sanitize certain filenames as described in SA-CORE-2020-012, along with other related vulnerabilities.

Therefore, File Example so is being removed from Examples until a version demonstrating file security best practices can added back in the future.

Group - Moderately critical - Information disclosure - SA-CONTRIB-2020-033

Project machine name: 
group
Date: 
2020-August-05

The Group module enables you to hand out permissions on a smaller subset, section or community of your website.

Under very specific circumstances, where two group types support the same content, yet hand out different permissions, non-members of the first group type may use the set of permissions of the 2nd group type for the grouped content.

This vulnerability is mitigated by the fact that you must already have a rare set-up and the two group types are configured in a way where one is more permissive than the other over the same type of content.

Group - Moderately critical - Information disclosure - SA-CONTRIB-2020-032

Project machine name: 
group
Date: 
2020-August-05

The Group module enables you to hand out permissions on a smaller subset, section or community of your website.

With the 1.1 security release, new code was introduced to ensure proper access for all entity types, but a mistake introduced unexpected access to unpublished nodes.

Hostmaster (Aegir) - Moderately critical - Access bypass, Arbitrary code execution - SA-CONTRIB-2020-031

Project machine name: 
hostmaster
Date: 
2020-July-29

Aegir is a powerful hosting system that sits alongside a LAMP or LEMP server to create, deploy and manage Drupal sites.

Given that

  • Aegir can use both Apache and Nginx Web servers,
  • Apache allows configuration-writing users to escalate their privileges to the superuser root, and
  • Aegir's operations are performed by the GNU/Linux user aegir,

It follows that:

Group - Critical - Information Disclosure - SA-CONTRIB-2020-030

Project machine name: 
group
Date: 
2020-July-29

This module enables you to hand out permissions on a smaller subset, section or community of your website.

The module used to leverage the node grants system but turned it off in its recent 8.x-1.0 release in favor of a system that works for ALL entity types, not just nodes. By doing so, some regular node access checks turned from neutral into allowed because of the way the node grants system operates.

Modal Form - Critical - Access bypass - SA-CONTRIB-2020-029

Project machine name: 
modal_form
Date: 
2020-July-22

The Modal form module is a toolset for quick start of using forms in modal windows.

Any form is available for view and submit when the modal_form module is installed. The only requirement is to know the form's fully-qualified class name.

Apigee Edge - Moderately critical - Access bypass - SA-CONTRIB-2020-028

Project machine name: 
apigee_edge
Date: 
2020-July-22

The Apigee Edge module allows connecting a Drupal site to Apigee Edge in order to build a developer portal. It contains an "Apigee Edge Teams" submodule that provides shared app functionality by allowing developers to be organized into teams.

The "Apigee Edge Teams" submodule has an information disclosure vulnerability. The "Add team member" form displays an email autocomplete field which can expose the email addresses of other accounts in the system.

Easy Breadcrumb - Moderately critical - Cross site scripting - SA-CONTRIB-2020-027

Project machine name: 
easy_breadcrumb
Date: 
2020-July-22

This module enables you to use the current URL (path alias) and the current page's title to automatically extract the breadcrumb's segments and its respective links then show them as breadcrumbs on your website.

The module doesn't sufficiently sanitize editor input in certain circumstances leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability requires the user have 'administer Easy Breadcrumb settings permission'.

Renderkit - Less critical - Access bypass - SA-CONTRIB-2020-026

Project machine name: 
renderkit
Date: 
2020-July-01

The renderkit module contains components which can transform the display of field items sent to it.

Some of these components do not respect the '#access' property on the field render element, and thus can make rendered field values visible to visitors who would otherwise not be allowed to see those field values.

This only occurs if all of the following conditions are true:

Internationalization - Moderately critical - Cross site scripting - SA-CONTRIB-2020-025

Project machine name: 
i18n
Date: 
2020-June-17

The Internationalization (i18n) module is a collection of modules to extend Drupal core multilingual capabilities and allows to build real life multilingual sites.

A value in the term translation module is displayed without being escaped leading to a Cross Site Scripting (XSS) vulnerability.

Open ReadSpeaker - Moderately critical - Cross site scripting - SA-CONTRIB-2020-024

Project machine name: 
open_readspeaker
Date: 
2020-June-10

This module enables you to add a configured ReadSpeaker button for text-to-speech for your site visitors.

The module doesn't sufficiently sanitize block configuration causing a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer blocks".

YubiKey - Less critical - Access bypass - SA-CONTRIB-2020-023

Project machine name: 
yubikey
Date: 
2020-June-10

This module enables you to use a Yubikey device to protect your Drupal user account. YubiKey is a secure method for logging into many websites using a cryptographically secure USB token.

The module doesn't sufficiently implement login flood control when the module is configured for YubiKey OTP only. This allows an attacker to attempt many YubiKey OTP codes. However, a brute force attack on this code is not practical in most situations given the length and randomness of the OTP codes.

Services - Moderately critical - Access bypass - SA-CONTRIB-2020-022

Project machine name: 
services
Date: 
2020-June-03

This module provides a standardized solution for building API's so that external clients can communicate with Drupal.

The module's taxonomy term index resource doesn't take into consideration certain access control tags provided (but unused) by core, that certain contrib modules depend on.

This vulnerability is mitigated by the fact your site must have the taxonomy term index resource enabled, your site must have a contributed module enabled which utilizes taxonomy term access control, and an attacker must know your api endpoint's path.

Password Reset Landing Page (PRLP) - Highly critical - Access bypass - SA-CONTRIB-2020-021

Project machine name: 
prlp
Date: 
2020-May-27

This module enables you to force a password update when using password reset link.
The module doesn't sufficiently validate the login URL allowing a malicious user to use a specially crafted URL to log in as another user.

Commerce Core - Moderately critical - Access bypass - SA-CONTRIB-2020-020

Project machine name: 
commerce
Date: 
2020-May-27

Drupal Commerce is used to build eCommerce websites and applications. It's possible to configure commerce to permit orders by anonymous users. In this configuration, customers who do not choose to create an account upon checkout completion remain anonymous, and the resulting orders are never assigned an owner.

reCAPTCHA v3 - Critical - Access bypass - SA-CONTRIB-2020-019

Project machine name: 
recaptcha_v3
Date: 
2020-May-13

The reCaptcha v3 module enables you to protect your forms using the Google reCaptcha V3.

If the reCaptcha v3 challenge succeeds, all the other form validations are bypassed. This makes it possible for attackers to submit invalid or incomplete forms.

This vulnerability only affects forms that are protected by reCaptcha v3 and have server side validation steps (e.g required field or custom validation functions).

Webform - Critical - Access bypass - SA-CONTRIB-2020-018

Project machine name: 
webform
Date: 
2020-May-13

This webform module enables you to build a 'Term checkboxes' element.

The module doesn't sufficiently check term 'view' access when rendering 'Term checkboxes' elements. Unpublished terms will always appear in the 'Term checkboxes' element.

Webform - Moderately critical - Access bypass - SA-CONTRIB-2020-017

Project machine name: 
webform
Date: 
2020-May-06

This module enables you to build forms and surveys in Drupal.

The Webform Node sub-module allows these forms to be associated with a Drupal node. The Webform Node module does not implement access checking in the same manner as other nodes and entities. As such, writers of custom modules which implement webform_node, node, or entity access checks may not achieve the intended access results for Webform Node content.

There is no known exploit of this vulnerability and the vulnerability only exists on sites with custom code and a node access module in use.

Webform - Critical - Access bypass - SA-CONTRIB-2020-016

Project machine name: 
webform
Date: 
2020-May-06

This webform module enables you to build 'Term select' and 'Term checkboxes' elements.

The module doesn't sufficiently check term 'view' access when rendering the 'Term select' and 'Term checkboxes' elements. Unpublished terms will always appear in the 'Term select' and 'Term checkboxes' elements.

Webform - Moderately critical - Cross site scripting - SA-CONTRIB-2020-015

Project machine name: 
webform
Date: 
2020-May-06

This module enables you to build forms and surveys in Drupal.

The module doesn't sufficiently sanitize Webform labels nor visibility conditions under the scenario of placing a block. When a webform block is placed and visible on a website any JavaScript code contained within the webform's label was executed.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Edit own webform" (or "Edit any webform").

Webform - Moderately critical - Cross site scripting - SA-CONTRIB-2020-014

Project machine name: 
webform
Date: 
2020-May-06

This module enables you to build forms and surveys in Drupal.

The module doesn't sufficiently filter user input under in the scenario when a webform is edited, namely the message related to character min/max counter does not undergo sufficient filtering and thus allows execution of JavaScript code through it.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Edit own webform" (or "Edit any webform").

Webform - Moderately critical - Cross site scripting - SA-CONTRIB-2020-013

Project machine name: 
webform
Date: 
2020-May-06

The Webform module allows site builders to create forms.

The module doesn't sufficiently prevent malicious code from being render via an options elements (i.e select menu, checkboxes, radios, etc...) under the scenario where the site builder allows the raw option value to be displayed.

This vulnerability is mitigated by the fact that site builder must be allowed to build webform and select raw as the options element's submission display.

Webform - Moderately critical - Access bypass - SA-CONTRIB-2020-012

Project machine name: 
webform
Date: 
2020-May-06

This module enables you to build forms and surveys in Drupal.

The module doesn't sufficiently validate data submitted into Webform Signature element during webform submission creation. This allows a malicious user to generate and extract HMAC hashes for arbitrary data. Such HMAC hashes are used across multiple spots in Drupal 8 core and contrib modules.

An extracted HMAC hash could be used to view restricted site content or log in as another user in certain situations.

Webform - Critical - Remote Code Execution - SA-CONTRIB-2020-011

Project machine name: 
webform
Date: 
2020-May-06

This module enables you to build forms and surveys in Drupal.

The module doesn't sufficiently filter webform element properties (attributes) under the scenario of editing a webform. Malicious user could craft such an attribute (#element_validate, for example) that would invoke execution of undesired PHP code.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Edit own webform" (or "Edit any webform").

JSON:API - Critical - Unsupported - SA-CONTRIB-2020-010

Project machine name: 
jsonapi
Date: 
2020-April-15

This module provides a JSON API standards-compliant API for accessing and
manipulating Drupal content and configuration entities.

The security team and module maintainers are marking this project unsupported. Both the 8.x-1.x and 8.x-2.x versions are unsupported, and users of either version are strongly encouraged to upgrade to a supported version of Drupal core, which includes a supported version of JSON:API.

Spamicide - Critical - Access bypass - SA-CONTRIB-2020-009

Project machine name: 
spamicide
Date: 
2020-April-08

The Spamicide module protects Drupal forms with a form field that is hidden from normal users, but visible to spam bots.

The module doesn't require appropriate permissions for administrative pages leading to an Access Bypass.

Svg Image - Critical - Cross site scripting - SA-CONTRIB-2020-008

Project machine name: 
svg_image
Date: 
2020-March-25

SVG Image module allows to upload SVG files.

The module did not sufficiently protect against malicious code inside SVG files leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have permission to upload an SVG file.

CKEditor 4 - WYSIWYG HTML editor - Moderately critical - Cross site scripting - SA-CONTRIB-2020-007

Project machine name: 
ckeditor
Date: 
2020-March-18

The CKEditor module (and its predecessor, FCKeditor module) allows Drupal to replace textarea fields with CKEditor 3.x/4.x (FCKeditor 2.x in case of FCKeditor module) - a visual HTML editor, sometimes called WYSIWYG editor.

Due to the usage of the JavaScript `eval()` function on non-filtered data in admin section, it was possible for a user with permission to create content visible in the admin area to inject specially crafted malicious script which causes Cross Site Scripting (XSS).

SAML Service Provider - Critical - Access bypass - SA-CONTRIB-2020-006

Project machine name: 
saml_sp
Date: 
2020-March-11

This module enables you to authenticate Drupal users using an external SAML Identity Provider.

If the site is configured to allow visitors to register for user accounts but administrator approval is required, the module doesn't sufficiently enforce the administrative approval requirement, in the case where the requesting user has already authenticated through SAML.

SVG Formatter - Critical - Cross site scripting - SA-CONTRIB-2020-005

Project machine name: 
svg_formatter
Date: 
2020-March-04

SVG Formatter module provides support for using SVG images on your website.

This security release fixes third-party dependencies included in or required by SVG Formatter. XSS bypass using entities and tab.

This vulnerability is mitigated by the fact that an attacker must be able to upload SVG files.

Profile - Moderately critical - Access Bypass - SA-CONTRIB-2020-004

Project machine name: 
profile
Date: 
2020-February-19

The Profile module enables you to allow users to have configurable user profiles.

The module doesn't sufficiently check access when creating a user profile. Users with the "create profiles" permission could create profiles for any users.

Views Bulk Operations (VBO) - Moderately critical - Access bypass - SA-CONTRIB-2020-003

Project machine name: 
views_bulk_operations
Date: 
2020-February-05

Views Bulk Operations provides enhancements to running bulk actions on views.

The module contains an access bypass vulnerability that might allow users to execute views actions that they should not have access to.

This vulnerability is mitigated by the fact that it only occurs in the case of customised action access (by means of hook_action_info_alter).

SpamSpan filter - Moderately critical - Cross site scripting - SA-CONTRIB-2020-002

Project machine name: 
spamspan
Date: 
2020-January-22

The SpamSpan module obfuscates email addresses to help prevent spambots from collecting them.

This module contains a spamspan twig filter which doesn't sanitize the passed HTML string.

This vulnerability is mitigated by the fact that sites must have custom twig template files that use the SpamSpan filter on a field that an attacker could populate. By default the SpamSpan module does not use the vulnerable twig filter.

Radix - Moderately critical - Cross site scripting - SA-CONTRIB-2020-001

Project machine name: 
radix
Date: 
2020-January-15

Radix is a base theme for Drupal, with Bootstrap 4, Sass, ES6 and BrowserSync built-in.

The module doesn't sufficiently filter menu titles when used in a dropdown in the main menu.

This vulnerability is mitigated by the fact that an attacker must have permission to edit a menu title used in the main menu.

Webform - Critical - Multiple vulnerabilities - SA-CONTRIB-2019-096

Project machine name: 
webform
Date: 
2019-December-11

This module enables you to create forms to collect information from users and report, analyze and distribute it by email.

The 7.x-3.x module doesn't sufficiently sanitize token values taken from query strings. If a query string token is used as the value of a markup component, an attacker can inject JavaScript into a page.

Permissions by Term - Moderately critical - Access bypass - SA-CONTRIB-2019-095

Project machine name: 
permissions_by_term
Date: 
2019-December-11

The Permissions by Term module extends Drupal by functionality for restricting access to single nodes via taxonomy terms.

The module doesn't sufficiently restrict access to node previews, when the Search API module is used to display nodes in search result lists.

Modal - Moderately critical - Access bypass - SA-CONTRIB-2019-094

Project machine name: 
modal_page
Date: 
2019-December-11

This project enables administrators to create modal dialogs.

The routes used by the module lacked proper permissions, allowing untrusted users to access, create and modify modal configurations.

Taxonomy access fix - Moderately critical - Access bypass - SA-CONTRIB-2019-093

Project machine name: 
taxonomy_access_fix
Date: 
2019-December-11

This module extends access handling of Drupal Core's Taxonomy module.

The module doesn't sufficiently check,

  • if a given entity should be access controlled, defaulting to allowing access even to unpublished Taxonomy Terms.
  • if certain administrative routes should be access controlled, defaulting to allowing access even to users without permission to access these administrative routes.

The vulnerability is mitigated by the facts, that

Smart Trim - Moderately critical - Cross site scripting - SA-CONTRIB-2019-092

Project machine name: 
smart_trim
Date: 
2019-December-11

The Smart Trim module allows site builders additional control with text summary fields.

The module doesn't sufficiently filter text when certain options are selected.

This vulnerability is mitigated by the fact that an attacker must have a role with the ability to create content on the site when certain options are selected for the trimmed output.

Floating Button Menu - Critical - Unsupported - SA-CONTRIB-2019-091

Project machine name: 
float_btn_menu
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Webform Multiple File Upload - Critical - Unsupported - SA-CONTRIB-2019-090

Project machine name: 
webform_multifile
Date: 
2019-November-13

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Pages

Subscribe with RSS Subscribe to Security advisories for contributed projects