- Advisory ID: DRUPAL-SA-CONTRIB-2014-076
- Project: Fasttoggle (third-party module)
- Version: 7.x
- Date: 2014-August-06
- Security risk: 11/25 (
Moderately Critical) AC:Basic/A:None/CI:None/II:None/E:Exploit/TD:25
- Vulnerability: Access bypass
Description
This module enables you to quickly toggle various user, node and field related settings via ajax links.
The recent 7.x-1.3 and 1.4 releases of the module include a rewrite of the access control which doesn't correctly implement support for the user status (allow/block) link.
This vulnerability is mitigated by the fact that the administrator must enable the link in the fasttoggle configuration and allow user profiles to be viewed by anonymous or logged in users. For user 1 to be affected, the administrator must also enable the fasttoggle setting that allows that account to be blocked via fasttoggle.
All uses of the Fasttoggle module are logged, so any invocations of the exploit will be recorded. Accounts can only be blocked or unblocked via the exploit.
CVE identifier(s) issued
- CVE-2014-5268
Versions affected
Drupal core is not affected. If you do not use the contributed Fasttoggle module,
there is nothing you need to do.
Solution
Install the latest version:
- If you use the Fasttoggle module for Drupal 7.x, upgrade to Fasttoggle 7.x-1.5
Also see the Fasttoggle project page.
Reported by
Fixed by
- Nigel Cunningham the module maintainer
Coordinated by
- Neil Drumm of the Drupal Security Team
- David Stoline of the Drupal Security Team
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at href="http://drupal.org/contact">http://drupal.org/contact.
Learn more about the Drupal Security team and their policies, href="http://drupal.org/writing-secure-code">writing secure code for Drupal, and href="http://drupal.org/security/secure-configuration">securing your site.