CERT-In Vulnerability Note
CIVN-2024-0079
Multiple Vulnerabilities in Drupal
Original Issue Date:March 01, 2024
Severity Rating: MEDIUM
Software Affected
- Coffee module for Drupal 10 version prior to 8.x-1.4
- Private Content module for Drupal 8.x version prior to 8.x-2.1
- node_access_rebuild_progressive module for Drupal 7 version prior to 7.x-1.2
Overview
Multiple vulnerabilities have been reported in Drupal modules which could be exploited by a remote attacker to gain unauthorized access to otherwise restricted functionality, alter critical or sensitive information and perform cross site scripting (XSS) attacks on the targeted system.
Description
1. Cross Site Scripting Vulnerability
The vulnerability exists due to insufficient escaping menu names when displaying them in the popup in the Coffee module. A remote attacker could exploit this vulnerability by sending a specially crafted request during web page generation. Successful exploitation of this vulnerability could allow a remote attacker to perform cross site scripting (XSS) attacks on the targeted system.
2. Access Bypass Vulnerability
The vulnerability exists due to incorrect grants access to private nodes under certain specific circumstances in the ¿Private Content module¿ and insufficient resetting the state of content access when the module is uninstalled in the ¿node_access_rebuild_progressive¿ module. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application. Successful exploitation of this vulnerability could allow a remote attacker to gain unauthorized access to otherwise restricted functionality.
Solution
Apply appropriate fixes as mentioned in Drupal Security Advisory:
https://www.drupal.org/sa-contrib-2024-011
https://www.drupal.org/sa-contrib-2024-012
https://www.drupal.org/sa-contrib-2024-013
Vendor Information
Drupal
https://www.drupal.org/sa-contrib-2024-011
https://www.drupal.org/sa-contrib-2024-012
https://www.drupal.org/sa-contrib-2024-013
References
Drupal
https://www.drupal.org/sa-contrib-2024-011
https://www.drupal.org/sa-contrib-2024-012
https://www.drupal.org/sa-contrib-2024-013
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|