Security update

ldap_integration 5.x-1.5

miglius - October 27, 2009 - 14:38
Download Size md5 hash
ldap_integration-5.x-1.5.tar.gz 30.26 KB 541ca5559f6c5c406c356a5f082dc489
Official release from CVS tag: DRUPAL-5--1-5
Last updated: October 27, 2009 - 14:41

This release fixes:
* The LDAP integration module does not implement a confirmation pages for the LDAP server activation/deactivation which could cause a CSRF attack.
* A user defined server name is not properly escaped on the administration pages which might lead to a XSS attacks.
* The user's LDAP data is not properly access controlled before displaying it in the user profile pages which allows unauthorized view of the data.
* Some user management access rules are ignored during the authentication process.

ldap_integration 6.x-1.0-beta2

miglius - October 27, 2009 - 14:37
Download Size md5 hash
ldap_integration-6.x-1.0-beta2.tar.gz 42.13 KB 2667c3e0c384fd3cb4a5ef0525d0578e
Official release from CVS tag: DRUPAL-6--1-0-BETA2
Last updated: October 27, 2009 - 14:41

This release fixes:
* The LDAP integration module does not implement a confirmation pages for the LDAP server activation/deactivation which could cause a CSRF attack.
* A user defined server name is not properly escaped on the administration pages which might lead to a XSS attacks.
* The user's LDAP data is not properly access controlled before displaying it in the user profile pages which allows unauthorized view of the data.
* Some user management access rules are ignored during the authentication process.

ShindigIntegrator 6.x-2.1

astha123 - October 27, 2009 - 05:37
Download Size md5 hash
ShindigIntegrator-6.x-2.1.tar.gz 152.85 KB 7143f373a45126145d276c8e2d3fb04d
Official release from CVS tag: DRUPAL-6--2-1
Last updated: October 27, 2009 - 05:41

XSS and CSRF issue fixes

workflow 5.x-2.4

jvandyk - October 23, 2009 - 15:44
Download Size md5 hash
workflow-5.x-2.4.tar.gz 42.17 KB 40cb43656d48ab8ba794bb49726723c8
Official release from CVS tag: DRUPAL-5--2-4
Last updated: October 23, 2009 - 15:47

Prevent users with 'administer workflow' permission from using workflow and state names containing XSS.

workflow 6.x-1.2

jvandyk - October 23, 2009 - 15:42
Download Size md5 hash
workflow-6.x-1.2.tar.gz 53.97 KB 770cdda21264ce088a58a896b817547f
Official release from CVS tag: DRUPAL-6--1-2
Last updated: October 23, 2009 - 15:47

Prevent users with 'administer workflow' permission from using workflow and state names containing XSS.

faq_ask 6.x-2.0

NancyDru - October 22, 2009 - 04:17
Download Size md5 hash
faq_ask-6.x-2.0.tar.gz 24.83 KB 2d5ab89266000785ee485a9b64067ed6
Official release from CVS tag: DRUPAL-6--2-0
Last updated: October 22, 2009 - 04:20

Significant rewrite to use native FAQ form. Allows better taxonomy support as well as standard node add-ons. Now supports free tagging.

Syndicate content
 
 

Drupal is a registered trademark of Dries Buytaert.