Drupal Cloud Module Cross Site Request Forgery Vulnerability
BID:102132
Info
Drupal Cloud Module Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 102132 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2017 12:00AM |
| Updated: | Dec 19 2017 10:01PM |
| Credit: | Tatar Balazs Janos |
| Vulnerable: |
Drupal Cloud 7.x-1.6 Drupal Cloud 7.x-1.5 Drupal Cloud 7.x-1.4 Drupal Cloud 7.x-1.3 Drupal Cloud 7.x-1.2 Drupal Cloud 7.x-1.1 Drupal Cloud 7.x-1.0 |
| Not Vulnerable: |
Drupal Cloud 7.x-1.7 |
Discussion
Drupal Cloud Module Cross Site Request Forgery Vulnerability
Cloud module for Drupal is prone to a cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Cloud module versions prior to 7.x-1.7 are vulnerable.
Cloud module for Drupal is prone to a cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Cloud module versions prior to 7.x-1.7 are vulnerable.
Solution / Fix
Drupal Cloud Module Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Drupal Cloud Module Cross Site Request Forgery Vulnerability
References:
References:
- Drupal Homepage (Drupal)
- Cloud - Critical - CSRF - SA-CONTRIB-2017-086 (drupal)