CAPTCHA
The module does not properly cancel security tokens after they are used. Someone could use this to bypass the spam protection on future form submissions. They could not view or alter any hidden information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker manually solves at least one spam test to collect valid tokens.
- Has it been used in attacksYes. It has been used in real attacks.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate CAPTCHA to 8.x-1.17 or 2.0.10, whichever branch you are on.
For developers: what the fix changed
The fix prevents CAPTCHA replay attacks by invalidating the session token (setting it to NULL) upon successful validation in `captcha_validate()` within `captcha.module`, and prevents retrieving solutions for already solved sessions. It also regenerates the token for 'show always' persistence in `src/Element/Captcha.php`.
Also in this release The release also includes test fixes, removes the VERSION key from libraries.yml, adds a data-nosnippet attribute to the CAPTCHA template, and makes minor accessibility and logging improvements.
.gitlab-ci.yml+2 −2captcha.inc+4 −0captcha.module+37 −29 fixmodules/image_captcha/image_captcha.libraries.yml+0 −3modules/image_captcha/js/image_captcha_refresh.js+1 −1src/Element/Captcha.php+15 −0 fixtemplates/captcha.html.twig+11 −9