Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2015-021
HistoryJan 14, 2015 - 12:00 a.m.

SA-CONTRIB-2015-021 - Content Analysis - Cross Site Scripting (XSS)

2015-01-1400:00:00
Drupal Security Team
www.drupal.org
6

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.967 High

EPSS

Percentile

99.7%

The Content Analysis module is an API designed to help modules that need to analyze content.

The module fails to sanitize user input in log messages, leading to a Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that only sites with dblog module enabled are affected.

CVE identifier(s) issued

  • CVE-2015-3364

Versions affected

  • Content Analysis 6.x-1.x versions prior to 6.x-1.7.

Drupal core is not affected. If you do not use the contributed Content Analysis module,
there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Content Analysis module for Drupal 6.x, upgrade to Content Analysis 6.x-1.7

Also see the Content Analysis project page.

Reported by

  • Pere Orga provisional member of the Drupal Security Team

Fixed by

Coordinated by

  • Pere Orga provisional member of the Drupal Security Team

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2015-021