Islandora
The module does not properly check access rights when block IDs are sent to its public address. A visitor could read restricted block content. They could not change any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module where a restricted block contains sensitive content and its ID is known or guessed.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Islandora to 2.19.0.
For developers: what the fix changed
The `islandora_advanced_search` sub-module has been completely removed from the codebase to resolve the access bypass vulnerability.
Also in this release The release also includes a fix for microservice rewrite for canonical event URLs.
modules/islandora_advanced_search/CONTRIBUTING.md+0 −73modules/islandora_advanced_search/LICENSE+0 −339modules/islandora_advanced_search/README.md+0 −261modules/islandora_advanced_search/css/islandora_advanced_search.form.css+0 −37modules/islandora_advanced_search/css/islandora_advanced_search.pager.css+0 −111modules/islandora_advanced_search/docs/advanced_search_block_settings.png+0 −0modules/islandora_advanced_search/docs/basic-input.png+0 −0modules/islandora_advanced_search/docs/contextual_filter_settings.png+0 −0modules/islandora_advanced_search/docs/demo.gif+0 −0modules/islandora_advanced_search/docs/enable_index_hierarchy.png+0 −0modules/islandora_advanced_search/docs/enable_index_hierarchy_processor.png+0 −0modules/islandora_advanced_search/docs/exclude_facet_settings_exclude.png+0 −0