Freelinking
It provides a filter framework for easier creation of links to other pages on a site or to external sites.
A user with the right access could see the titles of private web links. They could read this hidden text. They could not change or delete anything.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to use a text format configured to allow private external URLs to be crawled.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Freelinking to 4.0.3.
For developers: what the fix changed
The fix introduces a method in the External plugin to verify whether an external URL should be crawled, ensuring that private IP ranges are not accessed to retrieve page titles. It also changes the default setting to disable scraping and updates the configuration description to warn about potential exposure.
Also in this release The release includes updates to PHPStan configuration paths and adds a new unit test for external host URL checking.
phpstan.neon.dist+4 −4src/Plugin/freelinking/External.php+28 −5 fix