Internationalization Single Sign-On
Anyone without logging in could bypass access controls and log in as another user. They could then view private information and make changes to the website as that person.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if an attacker appears to come from the same internet address as the victim.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Internationalization Single Sign-On to 8.x-1.8.
For developers: what the fix changed
The fix updates token generation in src/Service/Token.php to use cryptographically secure random bytes instead of a predictable hash and changes database queries to use exact matches for tokens and escape user IPs in LIKE conditions.
Also in this release Minor docblock updates and query cleanups.
src/Controller/TokenController.php+1 −1src/Service/Token.php+11 −11 fix