[Security-news] SA-CONTRIB-2010-088 - Content Construction Kit (CCK) - Access Bypass

security-news at drupal.org security-news at drupal.org
Thu Aug 12 00:04:06 UTC 2010


  * Advisory ID: DRUPAL-SA-CONTRIB-2010-088
  * Project: Content Construction Kit (CCK) (third-party module)
  * Version: 6.x
  * Date: 2010-August-11
  * Security risk: Less Critical
  * Exploitable from: Remote
  * Vulnerability: Access Bypass

-------- DESCRIPTION  
---------------------------------------------------------

The Content Construction Kit (CCK) project is a set of modules that allows
you to add custom fields to nodes using a web browser. The CCK "Node
Reference" module provides a backend URL that is used for asynchronous
requests by the "autocomplete" widget to locate nodes the user can reference.
In some cases, this was not correctly checking that the user had field level
access to the source field, allowing direct queries to the backend URL to
return node titles and IDs which the user would otherwise be unable to
access. Note that as Drupal 5 CCK does not have any field access control
functionality, this issue only applies to the Drupal 6 version. This advisory
is a follow-up related to advisory SA-CONTRIB-2010-065 [1].
-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Content Construction Kit (CCK) module for Drupal 6.x versions prior to
    6.x-2.8

Drupal core is not affected. If you do not use the contributed Content
Construction Kit (CCK) [2] module, together with any node or field access
module there is nothing you need to do.
-------- SOLUTION  
------------------------------------------------------------

Install the latest version:
  * If you use the Content Construction Kit (CCK) module for Drupal 6.x
    upgrade to Content Construction Kit (CCK) 6.x-2.8 [3]

See also the Content Construction Kit (CCK) project page [4].
-------- REPORTED BY  
---------------------------------------------------------

  * Alexis Wilke [5]

-------- FIXED BY  
------------------------------------------------------------

  * Marc Ferran (markus_petrux) [6], module co-maintainer
  * Peter Wolanin (pwolanin) [7], of the Drupal security team

-------- CONTACT  
-------------------------------------------------------------

The Drupal security team [8] can be reached at security at drupal.org or via
the form at http://drupal.org/contact.

[1] http://drupal.org/node/829566
[2] http://drupal.org/project/cck
[3] http://drupal.org/node/880732
[4] http://drupal.org/project/cck
[5] http://drupal.org/user/356197
[6] http://drupal.org/user/39593
[7] http://drupal.org/user/49851
[8] http://drupal.org/security-team



More information about the Security-news mailing list