External Authentication
This module allows people to log into the website using accounts from other systems.
A logged in user could trick the system into matching their account with another person because of how the database reads text. This would let them view and alter information belonging to that other person. They could not read or change unrelated website settings.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies to sites using specific text sorting settings in their MySQL or MariaDB database.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate External Authentication to 2.0.13.
For developers: what the fix changed
The fix updates the authmap schema in externalauth.install to make the authname and provider columns binary safe. It also adds a strict PHP comparison in Authmap::getUid within src/Authmap.php to ensure the fetched values exactly match the supplied values.
Also in this release The release also adds tests to verify the collation fix and updates a spellcheck configuration file.
.gitlab-ci.yml+1 −1externalauth.install+59 −0 fixsrc/Authmap.php+6 −4 fix