This module integrates Drupal Commerce with the CyberSource payment gateway.
The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.
This issue only affects the Secure Acceptance Hosted Checkout gateway integration.
Install the latest version:
- If you use the Commerce CyberSource module, upgrade to Commerce CyberSource 8.x-1.10.
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Heine Deelstra (heine) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team