View online: https://www.drupal.org/psa-2017-001
* Advisory ID: DRUPAL-PSA-2017-001
* Project: Drupal core
* Version: 8.x
* Date: 2017-Apr-17
-------- DESCRIPTION
---------------------------------------------------------
There will be a security release of Drupal 8.3.x and 8.2.x on *April 19th
2017 between
17:00 - 18:00 UTC* that will fix a critical vulnerability. While we don't
normally provide security releases for unsupported minor releases [1], given
the potential severity, the 8.2.x release includes the fix for sites which
have not had a chance to update to 8.3.0. The Drupal Security Team urges you
to reserve time for core updates at that time because exploits are expected
to be developed within hours or days. Security release announcements will
appear at the standard announcement locations [2].
This vulnerability does not affect all Drupal 8 sites; it only affects sites
with certain configurations. It requires authenticated user access to
exploit. The security release announcement made on April 19th 2017, will
make it clear which configurations are affected. If this vulnerability
affects your site, you will need to update. Please set aside time on
Wednesday to look into this update.
Neither the Security Team, nor Security Team members, nor any Drupal-related
company are able to release any more information about this vulnerability
until the announcement is made in accordance with our security policies [3]
and responsible disclosure best practices [4].
.... Drupal 7 core is not affected by this issue.
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at Drupal.org or via the
contact form at https://www.drupal.org/contact [5].
Learn more about the Drupal Security team and their policies [6], writing
secure code for Drupal [7], and securing your site [8].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [9].
[1] https://www.drupal.org/core/release-cycle-overview
[2] https://www.drupal.org/security
[3]
https://www.drupal.org/drupal-security-team/security-team-procedures/drupal…
[4] https://en.wikipedia.org/wiki/Responsible_disclosure
[5] https://www.drupal.org/contact
[6] https://www.drupal.org/security-team
[7] https://www.drupal.org/writing-secure-code
[8] https://www.drupal.org/security/secure-configuration
[9] https://twitter.com/drupalsecurity
View online: https://www.drupal.org/node/2869190
* Advisory ID: DRUPAL-SA-CONTRIB-2017-042
* Project: Media [1] (third-party module)
* Date: 12-Apr-2017
-------- DESCRIPTION
---------------------------------------------------------
The Media module provides an extensible framework for managing files and
multimedia assets, regardless of whether they are hosted on your own site or
a 3rd party site - it is commonly referred to as a 'file browser to the
internet'.
-------- VERSIONS AFFECTED
---------------------------------------------------
* Only the 1.x branch is affected. The 2.x branch does not have this
vulnerability. /li>
Drupal core is not affected. If you do not use the contributed Media [2]
module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
If you use the Media 1.x branch you should upgrade to the 2.x branch.
Also see the Media [3] project page.
-------- REPORTED BY
---------------------------------------------------------
* Fabricio Bedoya [4]
-------- FIXED BY
------------------------------------------------------------
Not applicable
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [5].
Learn more about the Drupal Security team and their policies [6], writing
secure code for Drupal [7], and securing your site [8].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [9]
[1] https://www.drupal.org/project/media
[2] https://www.drupal.org/project/media
[3] https://www.drupal.org/project/media
[4] https://www.drupal.org/u/fafabedoya
[5] https://www.drupal.org/contact
[6] https://www.drupal.org/security-team
[7] https://www.drupal.org/writing-secure-code
[8] https://www.drupal.org/security/secure-configuration
[9] https://twitter.com/drupalsecurity
View online: https://www.drupal.org/node/2869156
* Advisory ID: DRUPAL-SA-CONTRIB-2014-041
* Project: Open Atrium Core [1] (third-party module), OA Comment [2]
(third-party module)
* Version: 7.x
* Date: 2017-April-12
* Security risk: 11/25 ( Moderately Critical)
AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:All [3]
* Vulnerability: Information Disclosure
-------- DESCRIPTION
---------------------------------------------------------
Open Atrium is a distribution the enables collaboration sites to be built.
It contains several custom modules to provide various functionality. While
content is often protected behind private groups, public content can also be
shared. When using Open Atrium as an internal Intranet, this "public"
content might be restricted to only logged in users by disabling anonymous
access to the site.
The oa_core and oa_comment modules do not properly respect the "view
published content" permission and allows anonymous users to view this
"public" content regardless of the permission setting.
This only affects sites that have disabled the "view published content"
permission for anonymous users, and only affects a small number of views.
-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------
* /A CVE identifier [4] will be requested, and added upon issuance, in
accordance with Drupal Security Team processes./
-------- VERSIONS AFFECTED
---------------------------------------------------
* Open Atrium distribution 7.x-2.x versions prior to 7.x-2.615
* oa_core 7.x-2.x versions prior to 7.x-2.84.
* oa_comment 7.x-2.x versions prior to 7.x-2.14.
Drupal core is not affected. If you do not use the contributed Open Atrium
Core [5] module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
Install the latest version of Open Atrium. Be sure to revert the following
features:
oa_comments, oa_core, oa_news, oa_river, oa_section, oa_sections
Also see the Open Atrium [6] project page.
-------- REPORTED BY
---------------------------------------------------------
* Mike Potter [7] of the Drupal Security Team
-------- FIXED BY
------------------------------------------------------------
* Mike Potter [8] the distribution maintainer and member of the Drupal
Security Team
-------- COORDINATED BY
------------------------------------------------------
* Mike Potter [9] of the Drupal Security Team
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [10].
Learn more about the Drupal Security team and their policies [11], writing
secure code for Drupal [12], and securing your site [13].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [14]
[1] https://www.drupal.org/project/oa_core
[2] https://www.drupal.org/project/oa_comment
[3] https://www.drupal.org/security-team/risk-levels
[4] http://cve.mitre.org/
[5] https://www.drupal.org/project/oa_core
[6] https://www.drupal.org/project/openatrium
[7] https://www.drupal.org/u/mpotter
[8] https://www.drupal.org/u/mpotter
[9] https://www.drupal.org/u/mpotter
[10] https://www.drupal.org/contact
[11] https://www.drupal.org/security-team
[12] https://www.drupal.org/writing-secure-code
[13] https://www.drupal.org/security/secure-configuration
[14] https://twitter.com/drupalsecurity
View online: https://www.drupal.org/node/2869141
* Advisory ID: DRUPAL-SA-CONTRIB-2017-39
* Project: Scheduler Workbench Integration [1] (third-party module)
* Date: 12-Apr-2017
-------- DESCRIPTION
---------------------------------------------------------
Provides integration between the Scheduler module and the Workbench
Moderation module.
The security team is marking this module unsupported. There is a known
security issue with the module that has not been fixed by the maintainer. If
you would like to maintain this module, please read:
https://www.drupal.org/node/251466
-------- VERSIONS AFFECTED
---------------------------------------------------
* All versions
Drupal core is not affected. If you do not use the contributed Scheduler
Workbench Integration [2] module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
If you use the Scheduler Workbench Integration module for Drupal you should
uninstall it.
Also see the Scheduler Workbench Integration [3] project page.
-------- REPORTED BY
---------------------------------------------------------
* Caroline Boyden [4]
-------- FIXED BY
------------------------------------------------------------
Not applicable
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [5].
Learn more about the Drupal Security team and their policies [6], writing
secure code for Drupal [7], and securing your site [8].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [9]
[1] https://www.drupal.org/project/scheduler_workbench
[2] https://www.drupal.org/project/scheduler_workbench
[3] https://www.drupal.org/project/scheduler_workbench
[4] https://www.drupal.org/user/657902
[5] https://www.drupal.org/contact
[6] https://www.drupal.org/security-team
[7] https://www.drupal.org/writing-secure-code
[8] https://www.drupal.org/security/secure-configuration
[9] https://twitter.com/drupalsecurity
View online: https://www.drupal.org/node/2869138
* Advisory ID: DRUPAL-SA-CONTRIB-2017-38
* Project: References [1] (third-party module)
* Date: 12-Apr-2017
-------- DESCRIPTION
---------------------------------------------------------
This project provides D7 versions of the 'node_reference' and
'user_reference' field types, that were part of the CCK package in D6, at
functional parity with the D6 counterparts.
The security team is marking this module unsupported. There is a known
security issue with the module that has not been fixed by the maintainer. If
you would like to maintain this module, please read:
https://www.drupal.org/node/251466
-------- VERSIONS AFFECTED
---------------------------------------------------
* All versions
Drupal core is not affected. If you do not use the contributed References [2]
module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
If you use the References module for Drupal you should uninstall it.
Also see the References [3] project page.
-------- REPORTED BY
---------------------------------------------------------
* Cash Williams [4] of the Drupal Security Team
-------- FIXED BY
------------------------------------------------------------
Not applicable
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [5].
Learn more about the Drupal Security team and their policies [6], writing
secure code for Drupal [7], and securing your site [8].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [9]
[1] https://www.drupal.org/project/references
[2] https://www.drupal.org/project/references
[3] https://www.drupal.org/project/references
[4] https://www.drupal.org/user/421070
[5] https://www.drupal.org/contact
[6] https://www.drupal.org/security-team
[7] https://www.drupal.org/writing-secure-code
[8] https://www.drupal.org/security/secure-configuration
[9] https://twitter.com/drupalsecurity
View online: https://www.drupal.org/node/2869127
* Advisory ID: DRUPAL-SA-CONTRIB-2017-36
* Project: Legal [1] (third-party module)
* Date: 12-Apr-2017
-------- DESCRIPTION
---------------------------------------------------------
Displays your Terms & Conditions to users who want to register, and requires
that they accept the T&C before their registration is accepted.
The security team is marking this module unsupported. There is a known
security issue with the module that has not been fixed by the maintainer. If
you would like to maintain this module, please read:
https://www.drupal.org/node/251466
-------- VERSIONS AFFECTED
---------------------------------------------------
* All versions
Drupal core is not affected. If you do not use the contributed Legal [2]
module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
If you use the Legal module for Drupal you should uninstall it.
Also see the Legal [3] project page.
-------- REPORTED BY
---------------------------------------------------------
* pbafe [4]
-------- FIXED BY
------------------------------------------------------------
Not applicable
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via
the contact form at https://www.drupal.org/contact [5].
Learn more about
the
Drupal Security team and their policies
, writing secure code for Drupal [6], and securing your site [7].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [8]
[1] https://www.drupal.org/project/legal
[2] https://www.drupal.org/project/legal
[3] https://www.drupal.org/project/legal
[4] https://www.drupal.org/user/3494981
[5] https://www.drupal.org/contact
[6] https://www.drupal.org/writing-secure-code
[7] https://www.drupal.org/security/secure-configuration
[8] https://twitter.com/drupalsecurity
View online: https://www.drupal.org/node/2869123
* Advisory ID: DRUPAL-SA-CONTRIB-2017-35
* Project: Book access [1] (third-party module)
* Date: 12-April-2017
-------- DESCRIPTION
---------------------------------------------------------
This module alters the book module permissions model by letting you specify
access/modify/delete rights on a per-book basis. Normally, book-related
permissions provided by drupal core apply across all books, but this module
will let you drill down as granular as to letting specific users have
specific rights for specific books.
The security team is marking this module unsupported. There is a known
security issue with the module that has not been fixed by the maintainer. If
you would like to maintain this module, please read:
https://www.drupal.org/node/251466
-------- VERSIONS AFFECTED
---------------------------------------------------
* All versions
Drupal core is not affected. If you do not use the contributed Book access
[2] module, there is nothing you need to do.
-------- SOLUTION
------------------------------------------------------------
If you use the Book access module for Drupal you should uninstall it.
Also see the Book access [3] project page.
-------- REPORTED BY
---------------------------------------------------------
* Ergun Kuru [4]
-------- FIXED BY
------------------------------------------------------------
Not applicable
-------- CONTACT AND MORE INFORMATION
----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [5].
Learn more about the Drupal Security team and their policies [6], writing
secure code for Drupal [7], and securing your site [8].
Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [9]
[1] https://www.drupal.org/project/book_access
[2] https://www.drupal.org/project/book_access
[3] https://www.drupal.org/project/book_access
[4] https://www.drupal.org/user/379181
[5] https://www.drupal.org/contact
[6] https://www.drupal.org/security-team
[7] https://www.drupal.org/writing-secure-code
[8] https://www.drupal.org/security/secure-configuration
[9] https://twitter.com/drupalsecurity