[Security-news] CKEditor Upload Image - Critical - Access bypass - SA-CONTRIB-2018-014
security-news at drupal.org
security-news at drupal.org
Wed Feb 21 19:13:52 UTC 2018
View online: https://www.drupal.org/sa-contrib-2018-014
Project: CKEditor Upload Image [1]
Date: 2018-February-21
Security risk: *Critical* 15∕25
AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass
Description:
This module enables you to drag and drop or paste images into CKEditor.
The module does not sufficiently verify users permissions, which leads to
anonymous users being able to upload files to the server.
Solution:
Install the latest version:
* If you use the CKEditor Upload Image module for Drupal 8.x, upgrade to
CKEditor Upload Image 8.x-1.5 [3]
Reported By:
* Jean-Francois Hovinne [4]
Fixed By:
* Jean-Francois Hovinne [5]
* Mer [6]
* Greg Knaddison [7] of the Drupal Security Team
Coordinated By:
* Greg Knaddison [8] of the Drupal Security Team
[1] https://www.drupal.org/project/ckeditor_uploadimage
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ckeditor_uploadimage/releases/8.x-1.5
[4] https://www.drupal.org/user/77723
[5] https://www.drupal.org/user/77723
[6] https://www.drupal.org/user/3513520
[7] https://www.drupal.org/user/36762
[8] https://www.drupal.org/user/36762
More information about the Security-news
mailing list