View online: https://www.drupal.org/psa-2020-06-24
Date: 2020-June-24
Description:
Previously, Drupal 7's end-of-life was scheduled for November 2021. Given the
impact of COVID-19 on budgets and businesses, we will be extending the end
of life until *November 28, 2022*. The Drupal Security Team will continue to
follow the Security Team processes [1] for Drupal 7 core and contributed
projects.
However, this means extra work from the Drupal community at large and the
security team in particular to review security reports, create patches, and
release security advisories for Drupal 7. This community effort will give
site owners more time while budgets recover, but the organizations that
sponsor security team members and the individual security team members who
volunteer their time could use your support. If you can, please donate to
support the end-of-life extension [2].
*Drupal 8 will still be end-of-life on November 2, 2021*, due to Symfony 3's
end of life [3]. However, since the upgrade path from Drupal 8 to Drupal 9 is
much easier, we don't anticipate the same impact on end-users.
.... What does this mean for my Drupal 7 site?
You can continue to run the site and get security updates via the normal
channels and processes. This will give you an extra year to work on
converting your site to Drupal 9.
.. Do I need to upgrade to Drupal 8 before I upgrade to Drupal 9?
Migrating directly from Drupal 7 to Drupal 9 is supported with the core
Migrate module. Read more on preparing a Drupal 7 site for Drupal 9 [4].
.... How can I help?
*Consider donating [5] to support this effort.* If you are a representative
of a large end-user of Drupal, we'd love you to join the Drupal Association
and the security team as a partner.
You can also consider getting more involved in fixing issues in the issue
queue [6] or joining the Security Team [7] as a way to support the effort.
.... What about Drupal 7 Vendor Extended Support?
The extended support will now run from November 2022 until November 2025.
You can read more about the Druapl 7 Vendor Extended Support program [8].
.... What about contributed projects?
The Security Team will continue to follow the Security Team processes [9] for
contributed projects. Contributed project maintainers are asked to consider
supporting existing Drupal 7 releases if they are able.
[1] https://www.drupal.org/drupal-security-team/security-team-procedures
[2] http://drupal.org/security-team/donate
[3] https://symfony.com/releases/3.4
[4]
https://www.drupal.org/docs/understanding-drupal/drupal-9-release-date-and-…
[5] http://drupal.org/security-team/donate
[6]
https://www.drupal.org/project/issues/drupal?text=&status=Open&priorities=A…
[7]
https://www.drupal.org/drupal-security-team/how-to-join-the-drupal-security…
[8]
https://www.drupal.org/drupal-security-team/information-for-organizations-i…
[9] https://www.drupal.org/drupal-security-team/security-team-procedures
View online: https://www.drupal.org/sa-contrib-2020-022
Project: Services [1]
Version: 7.x-3.x-dev
Date: 2020-June-03
Security risk: *Moderately critical* 11∕25
AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass
Description:
This module provides a standardized solution for building API's so that
external clients can communicate with Drupal.
The module's taxonomy term index resource doesn't take into consideration
certain access control tags provided (but unused) by core, that certain
contrib modules depend on.
This vulnerability is mitigated by the fact your site must have the taxonomy
term index resource enabled, your site must have a contributed module enabled
which utilizes taxonomy term access control, and an attacker must know your
api endpoint's path.
Solution:
Install the latest version:
* If you use the Services module for Drupal 7.x, upgrade to Services
7.x-3.26 [3]
Also see the Services [4] project page.
Reported By:
* Vadym Abramchuk [5]
Fixed By:
* Vadym Abramchuk [6]
* Tyler Frankenstein [7]
Coordinated By:
* Greg Knaddison [8] of the Drupal Security Team
[1] https://www.drupal.org/project/services
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/node/3144924
[4] https://www.drupal.org/project/services
[5] https://www.drupal.org/user/3216035
[6] https://www.drupal.org/user/3216035
[7] https://www.drupal.org/user/150680
[8] https://www.drupal.org/user/36762