Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-150
HistoryOct 03, 2012 - 12:00 a.m.

SA-CONTRIB-2012-150 - Twitter Pull - Cross Site Scripting (XSS)

2012-10-0300:00:00
Drupal Security Team
www.drupal.org
3

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

50.0%

Twitter Pull allows you to retrieve tweets from Twitter based on a user or search and display them on your site. It also includes integration with the boxes module to allow for simple placement of twitter feeds on various pages.

The module doesn’t sufficiently filter the data coming from Twitter which could result in script injection and XSS attacks.

This vulnerability is mitigated by the fact that Twitter is a generally trusted source and is unlikely to serve malicious content.

CVE: CVE-2012-5541

Versions affected

  • Twitter Pull 6.x-1.x versions prior to 6.x-1.3.
  • Twitter Pull 7.x-1.x versions prior to 7.x-1.0-rc3.

Drupal core is not affected. If you do not use the contributed Twitter Pull module, there is nothing you need to do.

Drupal core is not affected. If you do not use the contributed Twitter Pull module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Twitter Pull module for Drupal 6.x, upgrade to Twitter Pull 6.x-1.3
  • If you use the Twitter Pull module for Drupal 7.x, upgrade to Twitter Pull 7.x-1.0-rc3

Also see the Twitter Pull project page.

Reported by

Fixed by

Coordinated by

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

50.0%

Related for DRUPAL-SA-CONTRIB-2012-150