Actstream
It collects web activity from external services into native pieces of content for each user.
A visitor could alter settings for other user accounts on the website. They could read hidden configuration details and make unwanted changes to them.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Actstream to 2.1.1 or 2.0.1, whichever branch you are on.
For developers: what the fix changed
The fix updates the routing configuration file to require user update access rather than the generic access content permission for the accounts form route.
Also in this release The release also refactors hashtag filtering in the feed search module and updates class imports for the SimplePie library.
.cspell.json+17 −1README.md+1 −1actstream.api.php+2 −4actstream.routing.yml+1 −1 fixactstream_event/src/Entity/ActstreamEventInterface.php+1 −0actstream_facebook_page/src/Form/SettingsForm.php+1 −1actstream_feed/src/Hook/ActstreamFeedHooks.php+4 −2actstream_feed_search/composer.json+11 −0actstream_feed_search/src/Hook/ActstreamFeedSearchHooks.php+42 −14actstream_flickr/src/Hook/ActstreamFlickrHooks.php+2 −1actstream_instagram_search/src/Form/SettingsForm.php+1 −1actstream_mod_queue/src/Form/ModerationQueueForm.php+4 −4