[Security-news] Entity Reference - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-067

security-news at drupal.org security-news at drupal.org
Wed Aug 16 18:02:35 UTC 2017


View online: https://www.drupal.org/node/2902596

   * Advisory ID: DRUPAL-SA-CONTRIB-2017-067
   * Project: Entity reference [1]     (third-party module)
   * Version: 7.x
   * Date: 2017-August-16
   * Security risk: 12/25 ( Moderately Critical)
     AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Default [2]
   * Vulnerability: Access bypass

-------- DESCRIPTION
---------------------------------------------------------

The entity reference module provides a field type that can reference
arbitrary entities.

In a vulnerable configuration, an attacker could determine the titles of
nodes they do not have access to.

This is mitigated as only entity reference fields using the "simple" entity
selector are vulnerable, and the attack is not possible if any access control
(i.e. node access) is in place (the attacker's role is missing only the
"access content" permission to be able to view the content.)


-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------

   * /A CVE identifier [3] will be requested, and added upon issuance, in
     accordance with Drupal Security Team processes./

-------- VERSIONS AFFECTED
---------------------------------------------------

   * entityreference 7.x-1.x versions prior to 7.x-1.5.

Drupal core is not affected. If you do not use the contributed Entity
reference [4] module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Install the latest version:

   * If you use the entityreference module for Drupal 7.x, upgrade to
     entityreference 7.x-1.5 [5]

Also see the Entity reference [6] project page.

-------- REPORTED BY
---------------------------------------------------------

   * Greg Knaddison [7] of the Drupal Security Team
   * Aaron Ott [8]

-------- FIXED BY
------------------------------------------------------------

   * David Pascoe-Deslauriers [9] the module maintainer

-------- COORDINATED BY
------------------------------------------------------

   * Pere Orga [10] of the Drupal Security Team

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [11].

Learn more about the Drupal Security team and their policies [12], writing
secure code for Drupal [13], and  securing your site [14].

Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [15]


[1] https://www.drupal.org/project/entityreference
[2] https://www.drupal.org/security-team/risk-levels
[3] http://cve.mitre.org/
[4] https://www.drupal.org/project/entityreference
[5] https://www.drupal.org/node/2902583
[6] https://www.drupal.org/project/entityreference
[7] https://www.drupal.org/u/greggles
[8] https://www.drupal.org/user/154069
[9] https://www.drupal.org/u/spotzero
[10] https://www.drupal.org/user/2301194
[11] https://www.drupal.org/contact
[12] https://www.drupal.org/security-team
[13] https://www.drupal.org/writing-secure-code
[14] https://www.drupal.org/security/secure-configuration
[15] https://twitter.com/drupalsecurity



More information about the Security-news mailing list