Entity Share Websub
A visitor could force the website server to make requests to other web addresses. This might allow them to see information from other servers that the website connects to. They could not change or delete any information on the website itself.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Entity Share Websub to 1.1.2.
For developers: what the fix changed
The fix introduces a `CallbackValidator` service to validate WebSub callback URLs against internal and reserved IP ranges, preventing SSRF attacks. This validation is applied in `Hub.php` before making requests and in `Subscription.php` during subscription creation, with exceptions configurable via a new `CallbackValidatorSettingsForm`.
Also in this release The release also updates core version requirements to include Drupal 11, modifies GitLab CI templates, adds subscription deletion events, and updates logger dependency injection.
.cspell-project-words.txt+7 −0.gitlab-ci.yml+16 −0README.md+29 −0entity_share_websub.info.yml+1 −1modules/entity_share_websub_hub/config/install/entity_share_websub_hub.settings.yml+2 −0 fixmodules/entity_share_websub_hub/config/schema/entity_share_websub_hub.schema.yml+16 −0 fixmodules/entity_share_websub_hub/entity_share_websub_hub.info.yml+1 −1modules/entity_share_websub_hub/entity_share_websub_hub.install+117 −0 fixmodules/entity_share_websub_hub/entity_share_websub_hub.links.menu.yml+5 −0 fixmodules/entity_share_websub_hub/entity_share_websub_hub.permissions.yml+5 −0 fixmodules/entity_share_websub_hub/entity_share_websub_hub.post_update.php+42 −0 fixmodules/entity_share_websub_hub/entity_share_websub_hub.routing.yml+11 −0 fix