[Security-news] Facebook Pull - Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-011

security-news at drupal.org security-news at drupal.org
Wed Feb 8 19:49:27 UTC 2017


View online: https://www.drupal.org/node/2850873

   * Advisory ID: DRUPAL-SA-CONTRIB-2017-011
   * Project: Facebook Pull [1]     (third-party module)
   * Version: 7.x
   * Date: 2017-February-08
   * Security risk: 15/25 ( Critical)
     AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
   * Vulnerability: Cross Site Scripting

-------- DESCRIPTION
---------------------------------------------------------

This module enables you to add integration with Facebook API.

The module doesn't sufficiently sanitize incoming data from Facebook.

This vulnerability is mitigated by the fact that an attacker must have be
able to successfully pass malicious code through Facebook API or alter
facebooks DNS and recreate API endpoints.


-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------

   * /A CVE identifier [3] will be requested, and added upon issuance, in
     accordance with Drupal Security Team processes./

-------- VERSIONS AFFECTED
---------------------------------------------------

   * Facebook Pull versions prior to 7.x-3.1.

Drupal core is not affected. If you do not use the contributed Facebook Pull
[4] module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Install the latest version:

   * If you use the Facebook Pull module for Drupal 7.x, upgrade to Facebook
     Pull 7.x-3.1 [5]

Also see the Facebook Pull [6] project page.

-------- REPORTED BY
---------------------------------------------------------

   * Nedjo Rogers [7]

-------- FIXED BY
------------------------------------------------------------

   * Dave Ferrara [8] the module maintainer
   * Lee Rowlands [9] of the Drupal Security Team

-------- COORDINATED BY
------------------------------------------------------

   * Michael Hess [10] of the Drupal Security Team
   * David Snopek [11] of the Drupal Security Team

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at https://www.drupal.org/contact [12].

Learn more about the Drupal Security team and their policies [13], writing
secure code for Drupal [14], and  securing your site [15].

Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [16]


[1] https://www.drupal.org/project/facebook_pull
[2] https://www.drupal.org/security-team/risk-levels
[3] http://cve.mitre.org/
[4] https://www.drupal.org/project/facebook_pull
[5] https://www.drupal.org/project/facebook_pull/releases/7.x-3.1
[6] https://www.drupal.org/project/facebook_pull
[7] https://www.drupal.org/user/4481
[8] https://www.drupal.org/u/daveferrara1
[9] https://www.drupal.org/u/larowlan
[10] https://www.drupal.org/u/mlhess
[11] https://www.drupal.org/u/dsnopek
[12] https://www.drupal.org/contact
[13] https://www.drupal.org/security-team
[14] https://www.drupal.org/writing-secure-code
[15] https://www.drupal.org/security/secure-configuration
[16] https://twitter.com/drupalsecurity



More information about the Security-news mailing list