Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2015-026
HistoryJan 21, 2015 - 12:00 a.m.

SA-CONTRIB-2015-026 - Taxonews - Cross Site Scripting (XSS)

2015-01-2100:00:00
Drupal Security Team
www.drupal.org
6

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

0.967 High

EPSS

Percentile

99.7%

This module enables you to create blocks of nodes carrying a given taxonomy term.

The module doesn’t sufficiently escape term names in the blocks it builds leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer taxonomy” or the ability to create terms in some other way.

CVE identifier(s) issued

  • CVE-2015-3369

Versions affected

  • Taxonews 7.x-1.x versions prior to 7.x-1.1.
  • Taxonews 6.x-1.x versions prior to 6.x-1.2.

Drupal core is not affected. If you do not use the contributed Taxonews module,
there is nothing you need to do.

Solution

Install the latest version of Taxonews module:

  • For Drupal 7.x, upgrade to Taxonews 7.x-1.1
  • For Drupal 6.x, upgrade to Taxonews 6.x-1.2

Also see the Taxonews project page.

Reported by

  • Pere Orga provisional member of the Drupal Security Team

Fixed by

  • FGM the module maintainer

Coordinated by

  • Pere Orga provisional member of the Drupal Security Team

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2015-026