[Security-news] SA-CONTRIB-2010-099 - Views Bulk Operations - Access Bypass

security-news at drupal.org security-news at drupal.org
Wed Oct 6 21:36:52 UTC 2010


  * Advisory ID: DRUPAL-SA-CONTRIB-2010-099
  * Project: Views Bulk Operations (third-party module)
  * Version: 6.x
  * Date: 2010-October-6
  * Security risk: Not critical
  * Exploitable from: Remote
  * Vulnerability: Access bypass

-------- DESCRIPTION  
---------------------------------------------------------

Views Bulk Operations augments Views by allowing bulk operations to be
executed on the nodes and users displayed by a view. It does so by showing a
checkbox in front of each item, and adding a select box containing operations
that can be applied on the selected items. In some circumstances, a malicious
user could use Views Bulk Operation to cause user 0 (the anonymous user) to
be deleted. The effects of deleting user 0 vary depending on the system
configuration and the use of other contributed modules, ranging from trivial
errors to significant loss of functionality. The risk is mitigated by the
fact that a malicious user would need permission to a view that lets him/her
manage users through Views Bulk Operations in order to exploit this
vulnerability.
-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Views Bulk Operations for Drupal 6 prior to 6.x-1.10

Drupal core is not affected. If you do not use the contributed Views Bulk
Operations [1] module, there is nothing you need to do.

-------- SOLUTION  
------------------------------------------------------------

Install the latest version:

  * If you use the Views Bulk Operations module for Drupal 6.x upgrade to
    Views Bulk Operations 6.x-1.10 [2]

See also the Views Bulk Operations [3] project page.

-------- REPORTED BY  
---------------------------------------------------------

  * Joonas Kiminki (onaz [4])
  * Teemu Merikoski (tcmug [5])

-------- FIXED BY  
------------------------------------------------------------

  * Joonas Kiminki (onaz [6])
  * Teemu Merikoski (tcmug [7])

-------- CONTACT  
-------------------------------------------------------------

The Drupal security team [8] can be reached at security at drupal.org or via
the form at http://drupal.org/contact [9].


[1] http://drupal.org/project/views_bulk_operations
[2] http://drupal.org/node/933596
[3] http://drupal.org/project/views_bulk_operations
[4] http://drupal.org/user/158968
[5] http://drupal.org/user/515884
[6] http://drupal.org/user/158968
[7] http://drupal.org/user/515884
[8] http://drupal.org/security-team
[9] http://drupal.org/contact



More information about the Security-news mailing list