[Security-news] SA-CONTRIB-2014-056 - Commerce Moneris - Information Disclosure

security-news at drupal.org security-news at drupal.org
Wed May 21 15:56:24 UTC 2014


View online: https://drupal.org/node/2271823

   * Advisory ID: DRUPAL-SA-CONTRIB-2014-056
   * Project: Commerce Moneris [1] (third-party module)
   * Version: 7.x
   * Date: 2014-May-21
   * Security risk: Critical [2]
   * Exploitable from: Remote
   * Vulnerability: Information Disclosure

-------- DESCRIPTION
---------------------------------------------------------

Commerce Moneris is a payment module that integrates the Moneris payment
system with Drupal Commerce [3].

The module stores credit card data in a commerce order object unnecessarily
for the purpose of passing the credit card information to the payment
gateway. The credit card information is never removed from the order object
and is later saved in the clear as serialized data in the database.

This vulnerability is mitigated by the fact that an attacker must have access
to the database or the ability to execute PHP to output the raw or
unserialized data from the commerce order.


-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------

   * /A CVE identifier [4] will be requested, and added upon issuance, in
     accordance with Drupal Security Team processes./

-------- VERSIONS AFFECTED
---------------------------------------------------

   * Commerce Moneris 7.x-1.x versions prior to 7.x-1.4.

Drupal core is not affected. If you do not use the contributed Commerce
Moneris [5] module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Install the latest version:

   * If you use the Commerce Moneris module for Drupal 7.x, upgrade to 
Commerce
     Moneris 7.x-1.4 [6]

Also see the Commerce Moneris [7] project page.

-------- REPORTED BY
---------------------------------------------------------

   * Ryan Szrama [8]

-------- FIXED BY
------------------------------------------------------------

   * Scott Reeves [9], module co-maintainer

-------- COORDINATED BY
------------------------------------------------------

   * Rick Manelius [10] of the Drupal Security Team
   * Klaus Purer [11] of the Drupal Security Team

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [12].

Learn more about the Drupal Security team and their policies [13], writing
secure code for Drupal [14], and securing your site [15].

Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [16]


[1] http://drupal.org/project/commerce_moneris
[2] http://drupal.org/security-team/risk-levels
[3] https://drupal.org/project/commerce
[4] http://cve.mitre.org/
[5] http://drupal.org/project/commerce_moneris
[6] https://drupal.org/node/2271789
[7] http://drupal.org/project/commerce_moneris
[8] https://drupal.org/user/49344
[9] https://drupal.org/user/1167326
[10] https://drupal.org/user/680072
[11] https://drupal.org/user/262198
[12] http://drupal.org/contact
[13] http://drupal.org/security-team
[14] http://drupal.org/writing-secure-code
[15] http://drupal.org/security/secure-configuration
[16] https://twitter.com/drupalsecurity



More information about the Security-news mailing list