Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-022
HistoryFeb 15, 2012 - 12:00 a.m.

SA-CONTRIB-2012-022 - CDN - Information disclosure

2012-02-1500:00:00
Drupal Security Team
www.drupal.org
5

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

71.7%

CVE: CVE-2012-1645

The CDN module provides easy Content Delivery Network integration for Drupal sites. It alters file URLs, so that files are downloaded from a CDN instead of your web server.

When running in Origin Pull mode together with the “Far Future expiration” option, the module contains a vulnerability that allows anyone to view the contents of any *.php file within the site, including settings.php.

This vulnerability is mitigated by the fact that the site owner must have enabled the “Far Future expiration” option, and must be using the latest version of the module.

Versions affected

  • CDN version 6.x-2.2
  • CDN version 7.x-2.2

Drupal core is not affected. If you do not use the contributed CDN module, there is nothing you need to do.

Solution

Install the latest version:

See also the CDN project page.

Reported by

Fixed by

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

71.7%

Related for DRUPAL-SA-CONTRIB-2012-022