Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2015-124
HistoryJun 17, 2015 - 12:00 a.m.

LABjs - Less Critical - Open Redirect - SA-CONTRIB-2015-124

2015-06-1700:00:00
Drupal Security Team
www.drupal.org
6

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.967 High

EPSS

Percentile

99.7%

The LABjs module integrates LABjs with Drupal for web performance optimization.

The module ships with a modified version of the core Overlay JavaScript file, which is vulnerable to an open redirect attack (see SA-CORE-2015-002).

Only sites with the Overlay module enabled are vulnerable.

CVE identifier(s) issued

  • CVE-2015-3233

Versions affected

  • LABjs 7.x-1.x versions prior to 7.x-1.7.

Drupal core is not affected. If you do not use the contributed LABjs module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the LABjs module for Drupal 7.x, upgrade to LABjs 7.x-1.7.

Also see the LABjs project page.

Reported by

Fixed by

Coordinated by

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.967 High

EPSS

Percentile

99.7%